Merge ONAP certs into cacerts
[sdnc/oam.git] / installation / sdnc / src / main / docker / Dockerfile
1 # Prepare stage for multistage image build
2 ## START OF STAGE0 ##
3 FROM onap/ccsdk-odlsli-alpine-image:${ccsdk.docker.version} AS stage0
4
5 USER root
6
7 # copy onap
8 COPY opt /opt
9 RUN test -L /opt/sdnc || ln -s /opt/onap/sdnc /opt/sdnc
10 RUN mkdir $ODL_HOME/current/certs
11
12 # copy SDNC mvn artifacts to ODL repository
13 COPY system /tmp/system
14 RUN rsync -a /tmp/system $ODL_HOME
15 ## END OF STAGE0 ##
16
17 FROM onap/ccsdk-odlsli-alpine-image:${ccsdk.docker.version}
18
19 LABEL maintainer="SDN-C Team (sdnc@lists.onap.org)"
20
21 ENV SDNC_CONFIG_DIR /opt/onap/sdnc/data/properties
22 ENV SDNC_STORE_DIR /opt/onap/sdnc/data/stores
23 ENV SSL_CERTS_DIR /etc/ssl/certs
24 ENV JAVA_SECURITY_DIR $SSL_CERTS_DIR/java
25 ENV SDNC_NORTHBOUND_REPO mvn:org.onap.sdnc.northbound/sdnc-northbound-all/${sdnc.northbound.version}/xml/features
26 #CCSDKFEATUREVERSION specified in base image
27 ENV SDNR_NORTHBOUND_REPO mvn:org.onap.ccsdk.features.sdnr.northbound/sdnr-northbound-all/$CCSDKFEATUREVERSION/xml/features
28 ENV SDNR_WT_REPO mvn:org.onap.ccsdk.features.sdnr.wt/sdnr-wt-feature-aggregator/$CCSDKFEATUREVERSION/xml/features
29 ENV SDNR_DM_REPO mvn:org.onap.ccsdk.features.sdnr.wt/sdnr-wt-feature-aggregator-devicemanager/$CCSDKFEATUREVERSION/xml/features
30 ENV SDNC_KEYSTORE ${sdnc.keystore}
31 ENV SDNC_KEYPASS ${sdnc.keypass}
32 ENV SDNC_SECUREPORT ${sdnc.secureport}
33
34 USER root
35
36 COPY --from=stage0 --chown=odl:odl /opt /opt
37
38 # Add SDNC repositories to boot repositories
39 RUN cp $ODL_HOME/etc/org.apache.karaf.features.cfg $ODL_HOME/etc/org.apache.karaf.features.cfg.orig
40 RUN sed -i -e "\|featuresRepositories|s|$|,${SDNC_NORTHBOUND_REPO}, ${SDNR_NORTHBOUND_REPO}, ${SDNR_WT_REPO}, ${SDNR_DM_REPO}|"  $ODL_HOME/etc/org.apache.karaf.features.cfg
41 RUN sed -i -e "\|featuresBoot[^a-zA-Z]|s|$|,sdnc-northbound-all, sdnr-northbound-all, a1-adapter-northbound|"  $ODL_HOME/etc/org.apache.karaf.features.cfg
42 RUN sed -i "s/odl-restconf-all/odl-restconf-all,odl-netconf-topology/g"  $ODL_HOME/etc/org.apache.karaf.features.cfg
43
44 # install AAF configs
45 COPY aaa-app-config.xml $ODL_HOME/etc/opendaylight/datastore/initial/config/
46 RUN echo "cadi_prop_files=$SDNC_CONFIG_DIR/org.onap.sdnc.props" >> $ODL_HOME/etc/system.properties
47
48 # Install ssl and java certificates
49 COPY truststoreONAPall.jks $JAVA_SECURITY_DIR
50 COPY truststoreONAPall.jks $SDNC_STORE_DIR
51 RUN keytool -importkeystore -srckeystore $JAVA_SECURITY_DIR/truststoreONAPall.jks -srcstorepass changeit -destkeystore $JAVA_SECURITY_DIR/cacerts  -deststorepass changeit -noprompt
52 RUN keytool -importkeystore -srckeystore $JAVA_SECURITY_DIR/truststoreONAPall.jks -srcstorepass changeit -destkeystore /opt/java/openjdk/lib/security/cacerts  -deststorepass changeit -noprompt
53
54 # Secure with TLS
55 RUN echo org.osgi.service.http.secure.enabled=true >> $ODL_HOME/etc/custom.properties
56 RUN echo org.osgi.service.http.secure.port=$SDNC_SECUREPORT >> $ODL_HOME/etc/custom.properties
57 RUN echo org.ops4j.pax.web.ssl.keystore=$SDNC_STORE_DIR/$SDNC_KEYSTORE >> $ODL_HOME/etc/custom.properties
58 RUN echo org.ops4j.pax.web.ssl.password=$SDNC_KEYPASS >> $ODL_HOME/etc/custom.properties
59 RUN echo org.ops4j.pax.web.ssl.keypassword=$SDNC_KEYPASS >> $ODL_HOME/etc/custom.properties
60
61 RUN chown -R odl:odl /opt
62
63 USER odl
64
65 ENTRYPOINT /opt/onap/sdnc/bin/startODL.sh
66 EXPOSE 8181