aneurinandClaude Sonnet 5 4d4bace773
Build / build-and-push (push) Successful in 55s
Add build workflow
Builds and pushes the pass-cli image to code.aneur.in on every push to
main, based on zampler/zampler's build.yml pattern (registry login,
promote current latest to previous, build and push). Dropped everything
specific to that repo's own build (frontend/npm, Go cross-compilation,
multi-arch buildx) since this repo just builds one Dockerfile for one
architecture.

Uses its own BUILD_API_TOKEN secret, unrelated to Proton Pass -- build
workflows in this org are configured per-repo and don't go through
pass-cli, which is only for 'real world' deploy-time credentials.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-19 21:18:11 +01:00
2026-09-19 21:18:11 +01:00
2026-09-19 21:12:45 +01:00
2026-09-19 21:12:45 +01:00

pass-cli Docker image

A prebuilt, glibc-based container image for Proton Pass CLI (pass-cli).

Why this exists

pass-cli's official Linux binary is dynamically linked against glibc. It does not run under Alpine/musl, even with gcompat or libc6-compat installed — some of the symbols it needs (fcntl64, __res_init, ...) are glibc-specific and aren't shimmed. There's no official musl build and no official pass-cli image, so CI jobs that otherwise run in an Alpine-based container (like docker:cli) can't just apk add pass-cli or run the binary directly.

This image is a small debian:bookworm-slim base with a pinned, checksum-verified pass-cli binary installed, published so that kind of job can pull it and run pass-cli (or a script that calls it) without needing its own glibc environment.

Usage

There's no ENTRYPOINT -- just CMD ["pass-cli"]. Run bare:

docker run --rm code.aneur.in/cloud/pass-cli:<tag>

To run your own script against pass-cli instead (login, fetch an item, parse the result, etc.), mount it in and pass it as the command -- it replaces CMD entirely, no --entrypoint override needed:

docker run --rm \
  -e PROTON_PASS_PERSONAL_ACCESS_TOKEN \
  -v "$PWD/my-script.sh:/script.sh:ro" \
  code.aneur.in/cloud/pass-cli:<tag> \
  sh /script.sh

For one-off interactive use, prefix pass-cli explicitly, since args replace CMD rather than appending to it:

docker run --rm code.aneur.in/cloud/pass-cli:<tag> pass-cli --version

PROTON_PASS_KEY_PROVIDER is set to fs in the image by default, since a container has no kernel keyring for pass-cli's usual session storage.

Updating the pinned version

PASS_CLI_VERSION and PASS_CLI_SHA256 are build args at the top of the Dockerfile. Bump both together — get the new version's hash from https://proton.me/download/pass-cli/versions.json, or download the binary and check it yourself with sha256sum.

S
Description
No description provided
Readme
33 KiB
Languages
Dockerfile 100%