31 lines
1.2 KiB
Docker
31 lines
1.2 KiB
Docker
# Kong 3.9 — the declarative config uses fields (ai_metrics, rate-limiting
|
|
# redis block) introduced after 3.4; the running gateway is 3.9.1.
|
|
FROM kong:3.9
|
|
|
|
# Switch to root to install curl and set permissions
|
|
USER root
|
|
|
|
# Install curl for configuration import
|
|
RUN apt-get update && apt-get install -y curl && rm -rf /var/lib/apt/lists/*
|
|
|
|
# Copy custom entrypoint and configuration.
|
|
# kong.yml is the JWT-enforcing declarative config (RS256 via Keycloak public
|
|
# keys + jwt plugin on every protected route). Baked to the path Kong reads by
|
|
# default so `docker run` of this image is SECURE BY DEFAULT — no reliance on a
|
|
# runtime volume mount. (The previous image baked a config with `consumers: []`
|
|
# and no jwt plugin; see kong.yml.insecure-legacy for that reference.)
|
|
COPY entrypoint.sh /entrypoint.sh
|
|
COPY declarative/kong.yml /kong/declarative/kong.yml
|
|
|
|
# DBless + point Kong at the baked config. A volume mount at the same path can
|
|
# still override this for environment-specific configs (cluster vs local).
|
|
ENV KONG_DATABASE=off
|
|
ENV KONG_DECLARATIVE_CONFIG=/kong/declarative/kong.yml
|
|
|
|
# Make entrypoint executable
|
|
RUN chmod +x /entrypoint.sh
|
|
|
|
# Switch back to kong user
|
|
USER kong
|
|
|
|
ENTRYPOINT ["/entrypoint.sh"]
|