diff --git a/scripts/build-imgproxy-runtime-image.sh b/scripts/build-imgproxy-runtime-image.sh index dba1780..b250bb3 100644 --- a/scripts/build-imgproxy-runtime-image.sh +++ b/scripts/build-imgproxy-runtime-image.sh @@ -16,7 +16,9 @@ if [[ "$DRY_RUN" == 1 ]]; then fi command -v docker >/dev/null || { echo 'docker is required to build the imgproxy runtime image' >&2; exit 1; } -docker pull --platform linux/arm64 "$IMAGE_REF" +if ! docker image inspect "$IMAGE_REF" >/dev/null 2>&1; then + docker pull --platform linux/arm64 "$IMAGE_REF" +fi docker tag "$IMAGE_REF" "$IMAGE_TAG" docker save "$IMAGE_TAG" | gzip -c > "$OUT_DIR/imgproxy-runtime-image.tar.gz" shasum -a 256 "$OUT_DIR/imgproxy-runtime-image.tar.gz" > "$OUT_DIR/imgproxy-runtime-image.tar.gz.sha256" diff --git a/scripts/imgproxy-runtime-package.test.mjs b/scripts/imgproxy-runtime-package.test.mjs index a576790..1806cab 100644 --- a/scripts/imgproxy-runtime-package.test.mjs +++ b/scripts/imgproxy-runtime-package.test.mjs @@ -11,6 +11,11 @@ test('imgproxy runtime pins an arm64 image digest', () => { assert.match(dockerfile, /FROM darthsim\/imgproxy@sha256:[a-f0-9]{64}/); }); +test('builder reuses an already verified digest without a network pull', () => { + const builder = read('scripts/build-imgproxy-runtime-image.sh'); + assert.match(builder, /docker image inspect "\$IMAGE_REF"/); +}); + test('installer uses a read-only storage mount and both required ports', () => { const installer = read('scripts/install-imgproxy-runtime-prod.sh'); assert.match(installer, /-p 127\.0\.0\.1:20082:8080/);