Add Dockerfile and README

Prebuilt glibc image for pass-cli, so Alpine/musl-based CI jobs (e.g.
harmless-easy-bobcat's docker:cli-based deploy workflows) can pull and run
it without hitting missing glibc symbols.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-19 21:05:36 +01:00
co-authored by Claude Sonnet 5
parent 6876039bea
commit d534a21b09
2 changed files with 80 additions and 0 deletions
+29
View File
@@ -0,0 +1,29 @@
# pass-cli, glibc-linked, for hosts/CI where only an Alpine (musl) base is
# otherwise available. pass-cli's Linux binary needs real glibc symbols
# (fcntl64, __res_init, ...) that Alpine's gcompat/libc6-compat don't shim,
# so it can't run in e.g. the docker:cli image directly.
#
# ENTRYPOINT is pass-cli itself, so `docker run this-image <args>` behaves
# like `pass-cli <args>`. Callers who need to run their own script against
# pass-cli instead (login, fetch a note, parse it, etc.) override the
# entrypoint: `docker run --entrypoint sh this-image /path/to/script.sh`.
FROM debian:bookworm-slim
ARG PASS_CLI_VERSION=2.3.3
ARG PASS_CLI_SHA256=b5b49a8b3fd0af8830c0c1979f28ea0c90ccece73f59023a8bca8245d4b68da9
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates curl \
&& curl -fsSL -o /usr/local/bin/pass-cli \
"https://proton.me/download/pass-cli/${PASS_CLI_VERSION}/pass-cli-linux-x86_64" \
&& echo "${PASS_CLI_SHA256} /usr/local/bin/pass-cli" | sha256sum -c - \
&& chmod +x /usr/local/bin/pass-cli \
&& apt-get purge -y curl \
&& apt-get autoremove -y \
&& rm -rf /var/lib/apt/lists/*
# No kernel keyring in a container -- store the session on disk instead.
ENV PROTON_PASS_KEY_PROVIDER=fs
ENTRYPOINT ["pass-cli"]