Compare commits

...
3 Commits
Author SHA1 Message Date
aneurinandClaude Sonnet 5 e2f13547f9 Remove reference to cloud/cloud repo from README
That repo is private; this one is meant to be public once ready, so it
shouldn't point at a repo readers won't be able to open.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-19 21:11:43 +01:00
aneurinandClaude Sonnet 5 264478e0dc Drop ENTRYPOINT in favor of CMD ["pass-cli"]
Every real caller (code.aneur.in/cloud/cloud's deploy workflows) runs a
mounted-in script against pass-cli, not bare pass-cli args, so an
ENTRYPOINT override was needed on every invocation. With no ENTRYPOINT,
`docker run this-image sh /script.sh` just replaces CMD directly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-19 21:10:10 +01:00
aneurinandClaude Sonnet 5 d534a21b09 Add Dockerfile and README
Prebuilt glibc image for pass-cli, so Alpine/musl-based CI jobs (e.g.
harmless-easy-bobcat's docker:cli-based deploy workflows) can pull and run
it without hitting missing glibc symbols.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-19 21:05:36 +01:00
2 changed files with 87 additions and 0 deletions
+32
View File
@@ -0,0 +1,32 @@
# pass-cli, glibc-linked, for hosts/CI where only an Alpine (musl) base is
# otherwise available. pass-cli's Linux binary needs real glibc symbols
# (fcntl64, __res_init, ...) that Alpine's gcompat/libc6-compat don't shim,
# so it can't run in e.g. the docker:cli image directly.
#
# No ENTRYPOINT -- just CMD ["pass-cli"]. `docker run this-image` runs bare
# pass-cli; `docker run this-image <args>` replaces CMD entirely, so a
# caller running their own script against pass-cli (login, fetch a note,
# parse it, etc.) just does `docker run this-image sh /path/to/script.sh`
# with no --entrypoint override needed. The cost: `docker run this-image
# --version` doesn't work as shorthand -- write `docker run this-image
# pass-cli --version` instead.
FROM debian:bookworm-slim
ARG PASS_CLI_VERSION=2.3.3
ARG PASS_CLI_SHA256=b5b49a8b3fd0af8830c0c1979f28ea0c90ccece73f59023a8bca8245d4b68da9
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates curl \
&& curl -fsSL -o /usr/local/bin/pass-cli \
"https://proton.me/download/pass-cli/${PASS_CLI_VERSION}/pass-cli-linux-x86_64" \
&& echo "${PASS_CLI_SHA256} /usr/local/bin/pass-cli" | sha256sum -c - \
&& chmod +x /usr/local/bin/pass-cli \
&& apt-get purge -y curl \
&& apt-get autoremove -y \
&& rm -rf /var/lib/apt/lists/*
# No kernel keyring in a container -- store the session on disk instead.
ENV PROTON_PASS_KEY_PROVIDER=fs
CMD ["pass-cli"]
+55
View File
@@ -1 +1,56 @@
# pass-cli Docker image # pass-cli Docker image
A prebuilt, glibc-based container image for [Proton Pass
CLI](https://protonpass.github.io/pass-cli/) (`pass-cli`).
## Why this exists
`pass-cli`'s official Linux binary is dynamically linked against glibc. It
does not run under Alpine/musl, even with `gcompat` or `libc6-compat`
installed — some of the symbols it needs (`fcntl64`, `__res_init`, ...) are
glibc-specific and aren't shimmed. There's no official musl build and no
official pass-cli image, so CI jobs that otherwise run in an Alpine-based
container (like `docker:cli`) can't just `apk add pass-cli` or run the
binary directly.
This image is a small `debian:bookworm-slim` base with a pinned,
checksum-verified `pass-cli` binary installed, published so that kind of job
can pull it and run `pass-cli` (or a script that calls it) without needing
its own glibc environment.
## Usage
There's no `ENTRYPOINT` -- just `CMD ["pass-cli"]`. Run bare:
```sh
docker run --rm code.aneur.in/cloud/pass-cli:<tag>
```
To run your own script against `pass-cli` instead (login, fetch an item,
parse the result, etc.), mount it in and pass it as the command -- it
replaces `CMD` entirely, no `--entrypoint` override needed:
```sh
docker run --rm \
-e PROTON_PASS_PERSONAL_ACCESS_TOKEN \
-v "$PWD/my-script.sh:/script.sh:ro" \
code.aneur.in/cloud/pass-cli:<tag> \
sh /script.sh
```
For one-off interactive use, prefix `pass-cli` explicitly, since args
replace `CMD` rather than appending to it:
```sh
docker run --rm code.aneur.in/cloud/pass-cli:<tag> pass-cli --version
```
`PROTON_PASS_KEY_PROVIDER` is set to `fs` in the image by default, since a
container has no kernel keyring for `pass-cli`'s usual session storage.
## Updating the pinned version
`PASS_CLI_VERSION` and `PASS_CLI_SHA256` are build args at the top of the
`Dockerfile`. Bump both together — get the new version's hash from
`https://proton.me/download/pass-cli/versions.json`, or download the binary
and check it yourself with `sha256sum`.