Hi there,
I have a hopefully not so uncommon issue, so that someone can easily point me to a working solution (googl'ing did not help so far...):
We have bitbucket repostory that needs to build and push an docker image to a docker registry.
As the docker registry we want to use is a company-local-LAN system, we configured a self-hosted runner in docker-style.
Pipeline yml looks like this:
image: atlassian/default-image:3
pipelines:
custom:
dockerbuild:
- step:
name: "docker build"
runs-on:
- self.hosted
- linux
script:
# Prepare Docker Image with ZScaler certificates etc...
- |
bash <( curl --header "Authorization: Bearer $PIPELINE_HELPER_BEARERTOKEN" -sL --url "https://api.bitbucket.org/2.0/repositories/mycompany/pipelinehelperscripts/src/HEAD/PrepareDockerImage" )
# do docker stuff
- docker login dockerreg.mycompany.com -u $ISE_DOCKER_USER -p $ISE_DOCKER_PASS
- docker build -t dockerreg.mycompany.com/translationservice
- docker push dockerreg.mycompany.com/translationservice
services:
- docker
For securit reasony, the company is running Z-Scaler service, which hooks into every HTTPS connection with its own root-ca-certificate.
For "normal linux commands" like wget or curl, we need to put the z-scaler root ca certificate into a /usr/local/share/ca-certificates/ and run "update-ca-certificates". That's what the bash/curl command in the pipeline is doing...
But the docker commands totally ignore the certificates I added.
I also tried to apply the certificates to the docker-host system.
To make it clear:
On both system (docker host and docker container) I can use the certificates with wget, curl, ...
The docker-host system can successfully login to our registry without certificate issues.
But only on docker container level (run by the pipeline runner) the applied root-ca-certificate of Z-Scaler is *NOT* recognized by any docker command.
I'm pretty sure that other people with self-signed certificates do face the same problem.
So, is there someone out there who can give me a hint?
br,
Alex
[update]
What I found out so far:
If I run "docker version" inside the pipeline, I see that docker is somehow not using the docker server from the docker-host. That would explain why my docker container does now know the root-ca like my docker-host.
I found this documentation: https://support.atlassian.com/bitbucket-cloud/docs/run-docker-commands-in-bitbucket-pipelines/#Using-an-external-Docker-daemon
But: I have no clue how I can tell my pipeline to use the docker daemon from my docker-host system...