Image size optimization

Merged most RUN commands in Dockerfile.
Replaced ADD commands by COPY of the whole /etc and /usr in one
operation.
This commit is contained in:
Philippe Chepy 2016-03-11 12:19:20 +01:00
parent 87730cabbd
commit c47c651812
11 changed files with 47 additions and 60 deletions

View File

@ -4,81 +4,68 @@ MAINTAINER Thomas VIAL
ENV DEBIAN_FRONTEND noninteractive ENV DEBIAN_FRONTEND noninteractive
# Packages # Packages
RUN apt-get update && \ RUN apt-get update && \
apt-get upgrade -y --no-install-recommends && \ apt-get upgrade -y --no-install-recommends && \
apt-get install -y --no-install-recommends vim postfix sasl2-bin courier-imap courier-imap-ssl \ apt-get install -y --no-install-recommends \
postfix sasl2-bin libsasl2-modules courier-imap courier-imap-ssl \
courier-pop courier-pop-ssl courier-authdaemon supervisor gamin amavisd-new spamassassin clamav clamav-daemon libnet-dns-perl libmail-spf-perl \ courier-pop courier-pop-ssl courier-authdaemon supervisor gamin amavisd-new spamassassin clamav clamav-daemon libnet-dns-perl libmail-spf-perl \
pyzor razor arj bzip2 cabextract cpio file gzip nomarch p7zip pax unzip zip zoo rsyslog mailutils netcat \ pyzor razor arj bzip2 cabextract cpio file gzip nomarch p7zip pax unzip zip zoo rsyslog mailutils netcat \
opendkim opendkim-tools opendmarc curl fail2ban opendkim opendkim-tools opendmarc curl fail2ban
# Copy configuration files/executables
COPY /target /
# Configures Saslauthd # Configures Saslauthd
RUN rm -rf /var/run/saslauthd && ln -s /var/spool/postfix/var/run/saslauthd /var/run/saslauthd RUN rm -rf /var/run/saslauthd && ln -s /var/spool/postfix/var/run/saslauthd /var/run/saslauthd && \
RUN adduser postfix sasl adduser postfix sasl && \
RUN echo 'NAME="saslauthd"\nSTART=yes\nMECHANISMS="sasldb"\nTHREADS=0\nPWDIR=/var/spool/postfix/var/run/saslauthd\nPIDFILE="${PWDIR}/saslauthd.pid"\nOPTIONS="-n 0 -c -m /var/spool/postfix/var/run/saslauthd"' > /etc/default/saslauthd echo 'NAME="saslauthd"\nSTART=yes\nMECHANISMS="sasldb"\nTHREADS=0\nPWDIR=/var/spool/postfix/var/run/saslauthd\nPIDFILE="${PWDIR}/saslauthd.pid"\nOPTIONS="-n 0 -c -m /var/spool/postfix/var/run/saslauthd"' > /etc/default/saslauthd && \
\
# Configures Courier # Configures Courier \
RUN sed -i -r 's/daemons=5/daemons=1/g' /etc/courier/authdaemonrc sed -i -r 's/daemons=5/daemons=1/g' /etc/courier/authdaemonrc && \
RUN sed -i -r 's/authmodulelist="authpam"/authmodulelist="authuserdb"/g' /etc/courier/authdaemonrc sed -i -r 's/authmodulelist="authpam"/authmodulelist="authuserdb"/g' /etc/courier/authdaemonrc && \
\
# Enables Spamassassin and CRON updates # Enables Spamassassin and CRON updates \
RUN sed -i -r 's/^(CRON|ENABLED)=0/\1=1/g' /etc/default/spamassassin sed -i -r 's/^(CRON|ENABLED)=0/\1=1/g' /etc/default/spamassassin && \
\
# Enables Amavis # Enables Amavis \
RUN sed -i -r 's/#(@| \\%)bypass/\1bypass/g' /etc/amavis/conf.d/15-content_filter_mode sed -i -r 's/#(@| \\%)bypass/\1bypass/g' /etc/amavis/conf.d/15-content_filter_mode && \
RUN adduser clamav amavis adduser clamav amavis && \
RUN adduser amavis clamav adduser amavis clamav && \
RUN useradd -u 5000 -d /home/docker -s /bin/bash -p $(echo docker | openssl passwd -1 -stdin) docker useradd -u 5000 -d /home/docker -s /bin/bash -p $(echo docker | openssl passwd -1 -stdin) docker && \
\
# Enables Clamav # Enables Clamav \
RUN chmod 644 /etc/clamav/freshclam.conf chmod 644 /etc/clamav/freshclam.conf && \
RUN (crontab -l ; echo "0 1 * * * /usr/bin/freshclam --quiet") | sort - | uniq - | crontab - (crontab -l ; echo "0 1 * * * /usr/bin/freshclam --quiet") | sort - | uniq - | crontab - && \
RUN freshclam freshclam && \
\
# Configure DKIM (opendkim) # Configure DKIM (opendkim) \
RUN mkdir -p /etc/opendkim/keys mkdir -p /etc/opendkim/keys && \
ADD postfix/TrustedHosts /etc/opendkim/TrustedHosts chmod +x /usr/local/bin/generate-ssl-certificate && \
# DKIM config files \
ADD postfix/opendkim.conf /etc/opendkim.conf # Get LetsEncrypt signed certificate \
ADD postfix/default-opendkim /etc/default/opendkim curl https://letsencrypt.org/certs/lets-encrypt-x1-cross-signed.pem > /etc/ssl/certs/lets-encrypt-x1-cross-signed.pem && \
curl https://letsencrypt.org/certs/lets-encrypt-x2-cross-signed.pem > /etc/ssl/certs/lets-encrypt-x2-cross-signed.pem && \
# Configure DMARC (opendmarc) \
ADD postfix/opendmarc.conf /etc/opendmarc.conf # Start-mailserver script \
ADD postfix/default-opendmarc /etc/default/opendmarc chmod +x /usr/local/bin/start-mailserver.sh && \
\
# Configures Postfix # Cleanup
ADD postfix/main.cf /etc/postfix/main.cf apt-get clean && \
ADD postfix/master.cf /etc/postfix/master.cf
ADD postfix/sasl/smtpd.conf /etc/postfix/sasl/smtpd.conf
ADD bin/generate-ssl-certificate /usr/local/bin/generate-ssl-certificate
RUN chmod +x /usr/local/bin/generate-ssl-certificate
# Get LetsEncrypt signed certificate
RUN curl https://letsencrypt.org/certs/lets-encrypt-x1-cross-signed.pem > /etc/ssl/certs/lets-encrypt-x1-cross-signed.pem
RUN curl https://letsencrypt.org/certs/lets-encrypt-x2-cross-signed.pem > /etc/ssl/certs/lets-encrypt-x2-cross-signed.pem
# Start-mailserver script
ADD start-mailserver.sh /usr/local/bin/start-mailserver.sh
RUN chmod +x /usr/local/bin/start-mailserver.sh
RUN apt-get clean && \
rm -rf /tmp/* /var/tmp/* && \ rm -rf /tmp/* /var/tmp/* && \
rm -rf /var/lib/apt/lists/* rm -rf /var/lib/apt/lists/*
# SMTP ports
EXPOSE 25
EXPOSE 587
# IMAP ports # SMTP | IMAP | POP3
EXPOSE 143 EXPOSE 25 587 143 993 110 995
EXPOSE 993
# POP3 ports
EXPOSE 110
EXPOSE 995
CMD /usr/local/bin/start-mailserver.sh CMD /usr/local/bin/start-mailserver.sh