2017-01-31 09:26:57 +00:00
|
|
|
# Pin the base image to a specific hash for maximum reproducibility.
|
2018-11-03 17:25:40 +00:00
|
|
|
# It will probably still work on newer images, though, unless Debian
|
2017-01-31 09:26:57 +00:00
|
|
|
# changes some compiler optimisations (unlikely).
|
2019-02-01 09:25:29 +00:00
|
|
|
#FROM ocaml/opam2:debian-9-ocaml-4.07
|
2019-06-15 12:48:01 +01:00
|
|
|
FROM ocaml/opam2@sha256:74fb6e30a95e1569db755b3c061970a8270dfc281c4e69bffe2cf9905d356b38
|
2017-01-28 13:44:21 +00:00
|
|
|
|
|
|
|
# Pin last known-good version for reproducible builds.
|
2017-01-31 09:26:57 +00:00
|
|
|
# Remove this line (and the base image pin above) if you want to test with the
|
|
|
|
# latest versions.
|
2019-06-15 12:48:01 +01:00
|
|
|
RUN git fetch origin && git reset --hard d28fedaa8a077a429bd7bd79cbc19eb90e01c040 && opam update
|
2017-01-28 13:44:21 +00:00
|
|
|
|
2018-11-03 17:25:40 +00:00
|
|
|
RUN sudo apt-get install -y m4 libxen-dev pkg-config
|
2019-04-16 18:05:08 +01:00
|
|
|
RUN opam install -y vchan mirage-xen-ocaml mirage-xen-minios io-page mirage-xen mirage mirage-nat mirage-qubes
|
2017-01-09 16:45:16 +00:00
|
|
|
RUN mkdir /home/opam/qubes-mirage-firewall
|
|
|
|
ADD config.ml /home/opam/qubes-mirage-firewall/config.ml
|
|
|
|
WORKDIR /home/opam/qubes-mirage-firewall
|
2017-03-05 16:31:04 +00:00
|
|
|
RUN opam config exec -- mirage configure -t xen && make depend
|
|
|
|
CMD opam config exec -- mirage configure -t xen && \
|
2017-01-09 16:45:16 +00:00
|
|
|
opam config exec -- make tar
|