# Default arguments ARG nanoserverImage='mcr.microsoft.com/windows/nanoserver:1903' ARG powershellImage='mcr.microsoft.com/powershell:nanoserver-1903' ARG teamcityWindowsservercoreImage='teamcity-agent:EAP-windowsservercore-1903' # The list of required arguments # ARG nanoserverImage # ARG powershellImage # ARG teamcityWindowsservercoreImage FROM ${powershellImage} AS dotnet COPY scripts/*.cs /scripts/ SHELL ["pwsh", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue';"] ARG teamcityWindowsservercoreImage FROM ${teamcityWindowsservercoreImage} AS tools # Workaround for https://github.com/PowerShell/PowerShell-Docker/issues/164 ARG nanoserverImage FROM ${nanoserverImage} ENV ProgramFiles="C:\Program Files" \ # set a fixed location for the Module analysis cache PSModuleAnalysisCachePath="C:\Users\ContainerUser\AppData\Local\Microsoft\Windows\PowerShell\docker\ModuleAnalysisCache" \ # Persist %PSCORE% ENV variable for user convenience PSCORE="$ProgramFiles\PowerShell\pwsh.exe" # PowerShell COPY --from=dotnet ["C:/Program Files/PowerShell", "C:/Program Files/PowerShell"] # In order to set system PATH, ContainerAdministrator must be used USER ContainerAdministrator RUN setx /M PATH "%PATH%;%ProgramFiles%\PowerShell" USER ContainerUser # intialize powershell module cache RUN pwsh -NoLogo -NoProfile -Command " \ $stopTime = (get-date).AddMinutes(15); \ $ErrorActionPreference = 'Stop' ; \ $ProgressPreference = 'SilentlyContinue' ; \ while(!(Test-Path -Path $env:PSModuleAnalysisCachePath)) { \ Write-Host "'Waiting for $env:PSModuleAnalysisCachePath'" ; \ if((get-date) -gt $stopTime) { throw 'timout expired'} \ Start-Sleep -Seconds 6 ; \ }" # JDK COPY --from=tools ["C:/Program Files/Java/OpenJDK", "C:/Program Files/Java/OpenJDK"] # Git COPY --from=tools ["C:/Program Files/Git", "C:/Program Files/Git"] # .NET COPY --from=tools ["C:/Program Files/dotnet", "C:/Program Files/dotnet"] COPY --from=tools /BuildAgent /BuildAgent EXPOSE 9090 # Configuration file for TeamCity agent ENV CONFIG_FILE="C:\BuildAgent\conf\buildAgent.properties" \ # Java home directory JAVA_HOME="C:\Program Files\Java\OpenJDK" \ # Opt out of the telemetry feature DOTNET_CLI_TELEMETRY_OPTOUT=true \ # Disable first time experience DOTNET_SKIP_FIRST_TIME_EXPERIENCE=true \ # Configure Kestrel web server to bind to port 80 when present ASPNETCORE_URLS=http://+:80 \ # Enable detection of running in a container DOTNET_RUNNING_IN_CONTAINER=true \ # Enable correct mode for dotnet watch (only mode supported in a container) DOTNET_USE_POLLING_FILE_WATCHER=true \ # Skip extraction of XML docs - generally not useful within an image/container - helps perfomance NUGET_XMLDOC_MODE=skip # Use ContainerAdministrator to update permissions and PATH USER ContainerAdministrator # Create missing directories required for volumes, reset any potentially conflicting ACLs, ... # ... grant Permissions for ContainerUser (Default Account), OI - Object Inherit, CI - Container Inherit, ... # ... F - full control, /T - apply to subfolders & files RUN setx /M PATH "%PATH%;%JAVA_HOME%\bin;C:\Program Files\Git\cmd;C:\Program Files\dotnet" && \ if not exist C:\BuildAgent\logs md C:\BuildAgent\logs && \ if not exist C:\BuildAgent\work md C:\BuildAgent\work && \ if not exist C:\BuildAgent\conf md C:\BuildAgent\conf && \ type nul > C:\BuildAgent\logs\.keep && \ type nul > C:\BuildAgent\work\.keep && \ type nul > C:\BuildAgent\conf\.keep && \ if exist C:\BuildAgent\conf\buildAgent.properties del C:\BuildAgent\conf\buildAgent.properties # Reset and grant permissions in PowerShell for proper error handling SHELL ["pwsh", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue';"] RUN Write-Host 'Resetting ACLs...' ; \ icacls.exe C:\BuildAgent /reset /T ; \ if ($LASTEXITCODE -ne 0) { throw ('icacls reset failed with exit code ' + $LASTEXITCODE) } ; \ Write-Host 'Granting permissions...' ; \ icacls.exe C:\BuildAgent /grant:r 'DefaultAccount:(OI)(CI)F' /grant:r 'Users:(OI)(CI)F' /T ; \ if ($LASTEXITCODE -ne 0) { throw ('icacls grant failed with exit code ' + $LASTEXITCODE) } ; \ <# Canonicalizing ACLs to prevent issues such as TW-100061 #> \ Write-Host 'Canonicalizing ACLs...' ; \ $acl = Get-Acl 'C:\BuildAgent'; Set-Acl 'C:\BuildAgent' $acl; \ Get-ChildItem 'C:\BuildAgent' -Recurse -Force | ForEach-Object { $a = Get-Acl $_.FullName; Set-Acl $_.FullName $a }; \ $acl = Get-Acl 'C:\BuildAgent'; if (-not $acl.AreAccessRulesCanonical) { throw 'ACLs are not canonical after Set-Acl on C:\BuildAgent' }; \ Write-Host 'Verifying permissions:' ; \ icacls.exe C:\BuildAgent\conf ; \ icacls.exe C:\BuildAgent\* SHELL ["cmd", "/S", "/C"] USER ContainerUser # NB! The legacy builder discards permissions changes after the volune has been initialized => `icacls` has to be executed earlier VOLUME C:/BuildAgent/conf # Trigger first run experience by running arbitrary cmd to populate local package cache RUN dotnet help CMD ["pwsh", "./BuildAgent/run-agent.ps1"]