# pass-cli, glibc-linked, for hosts/CI where only an Alpine (musl) base is # otherwise available. pass-cli's Linux binary needs real glibc symbols # (fcntl64, __res_init, ...) that Alpine's gcompat/libc6-compat don't shim, # so it can't run in e.g. the docker:cli image directly. # # ENTRYPOINT is pass-cli itself, so `docker run this-image ` behaves # like `pass-cli `. Callers who need to run their own script against # pass-cli instead (login, fetch a note, parse it, etc.) override the # entrypoint: `docker run --entrypoint sh this-image /path/to/script.sh`. FROM debian:bookworm-slim ARG PASS_CLI_VERSION=2.3.3 ARG PASS_CLI_SHA256=b5b49a8b3fd0af8830c0c1979f28ea0c90ccece73f59023a8bca8245d4b68da9 RUN apt-get update \ && apt-get install -y --no-install-recommends ca-certificates curl \ && curl -fsSL -o /usr/local/bin/pass-cli \ "https://proton.me/download/pass-cli/${PASS_CLI_VERSION}/pass-cli-linux-x86_64" \ && echo "${PASS_CLI_SHA256} /usr/local/bin/pass-cli" | sha256sum -c - \ && chmod +x /usr/local/bin/pass-cli \ && apt-get purge -y curl \ && apt-get autoremove -y \ && rm -rf /var/lib/apt/lists/* # No kernel keyring in a container -- store the session on disk instead. ENV PROTON_PASS_KEY_PROVIDER=fs ENTRYPOINT ["pass-cli"]