Prebuilt glibc image for pass-cli: a small debian:bookworm-slim base with a pinned, checksum-verified pass-cli binary, published so Alpine/musl-based CI jobs can pull and run it without hitting missing glibc symbols (fcntl64, __res_init, etc, which gcompat/libc6-compat don't shim). No ENTRYPOINT, just CMD ["pass-cli"] -- callers running their own script against pass-cli mount it in and pass it as the command directly (`docker run image sh /script.sh`), no --entrypoint override needed. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
pass-cli Docker image
A prebuilt, glibc-based container image for Proton Pass
CLI (pass-cli).
Why this exists
pass-cli's official Linux binary is dynamically linked against glibc. It
does not run under Alpine/musl, even with gcompat or libc6-compat
installed — some of the symbols it needs (fcntl64, __res_init, ...) are
glibc-specific and aren't shimmed. There's no official musl build and no
official pass-cli image, so CI jobs that otherwise run in an Alpine-based
container (like docker:cli) can't just apk add pass-cli or run the
binary directly.
This image is a small debian:bookworm-slim base with a pinned,
checksum-verified pass-cli binary installed, published so that kind of job
can pull it and run pass-cli (or a script that calls it) without needing
its own glibc environment.
Usage
There's no ENTRYPOINT -- just CMD ["pass-cli"]. Run bare:
docker run --rm code.aneur.in/cloud/pass-cli:<tag>
To run your own script against pass-cli instead (login, fetch an item,
parse the result, etc.), mount it in and pass it as the command -- it
replaces CMD entirely, no --entrypoint override needed:
docker run --rm \
-e PROTON_PASS_PERSONAL_ACCESS_TOKEN \
-v "$PWD/my-script.sh:/script.sh:ro" \
code.aneur.in/cloud/pass-cli:<tag> \
sh /script.sh
For one-off interactive use, prefix pass-cli explicitly, since args
replace CMD rather than appending to it:
docker run --rm code.aneur.in/cloud/pass-cli:<tag> pass-cli --version
PROTON_PASS_KEY_PROVIDER is set to fs in the image by default, since a
container has no kernel keyring for pass-cli's usual session storage.
Updating the pinned version
PASS_CLI_VERSION and PASS_CLI_SHA256 are build args at the top of the
Dockerfile. Bump both together — get the new version's hash from
https://proton.me/download/pass-cli/versions.json, or download the binary
and check it yourself with sha256sum.