Add ssh parameter support for image builds - #642
Conversation
|
@sowmya-sl thanks for the PR, please sign your commit as DCO bot says |
b91b1c7 to
23b0c67
Compare
|
/packit retest-failed |
|
@inknos Let me know if anything needs to be added from the server side. |
|
/packit retest-failed |
| manifest (str) - add the image to the specified manifest list. | ||
| Creates manifest list if it does not exist. | ||
| secrets (list[str]) - Secret files/envs to expose to the build | ||
| ssh (list[str]) - SSH agent socket or keys to expose to the build |
There was a problem hiding this comment.
I would add an example of how content should look, or refer that content should look like podman build --ssh.
| params["secrets"] = json.dumps(kwargs.get("secrets")) | ||
|
|
||
| if "ssh" in kwargs: | ||
| params["ssh"] = json.dumps(kwargs.get("ssh")) |
There was a problem hiding this comment.
Non-blocking: What if kwargs.get("ssh") returns an empty array?
Allow passing SSH agent sockets or keys to the build API, similar to the existing secrets parameter support. Review comments: - Add usage examples and reference to podman build --ssh in the ssh parameter docstring Signed-off-by: sowmya-sl <lsowmyanarayanan@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
|
@sowmya-sl thanks @Honny1 I think a change is needed in podman like this. it's just a POC, what do you think? |
I think yes. |
Pass SSH agent sockets or keys through the build API, mirroring the existing secrets parameter support. - Add `ssh` query parameter to the build endpoint - Parse and move SSH key files out of the build context (same pattern as secrets) - Wire SSHSources into buildah CommonBuildOptions - Add client-side SSH key file handling in Go bindings - Add e2e test for --ssh flag with key file Related: containers/podman-py#602 Related: containers/podman-py#642 Signed-off-by: Nicola Sella <nsella@redhat.com>
| secrets (list[str]) - Secret files/envs to expose to the build | ||
| ssh (list[str]) - SSH agent socket or keys to expose to the build. | ||
| Format is the same as ``podman build --ssh``, e.g. | ||
| ``["default"]`` or ``["src=/path/to/key"]``. |
There was a problem hiding this comment.
| ``["default"]`` or ``["src=/path/to/key"]``. | |
| ``["default"]`` or ``["mykey=/path/to/key"]``. |
https://docs.podman.io/en/latest/markdown/podman-build.1.html#ssh-default-id-socket
specifies the format as default | id[=socket], so valid examples are "default", "default=/path/to/socket", or "mykey=/path/to/key".
|
@inknos Any update on podman side? |
Allow passing SSH agent sockets or keys to the build API, similar to the existing secrets parameter support.
Fixes: #602