Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/ci-warm-caches.yml
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,12 @@ concurrency:
group: warm-caches-${{ github.ref }}
cancel-in-progress: true

env:
# Pull and tag images straight from Docker Hub, never through registry.defectdojo.com:
# the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI
# pulls must not count as installs.
DD_IMAGE_REGISTRY: docker.io

jobs:
warm-migrated-db:
name: Warm Migrated Database Snapshot
Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/fetch-oas.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,10 @@ on:
required: true

env:
# Pull and tag images straight from Docker Hub, never through registry.defectdojo.com:
# the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI
# pulls must not count as installs.
DD_IMAGE_REGISTRY: docker.io
release_version: ${{ github.event.inputs.version || github.event.inputs.release_number }}

jobs:
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/integration-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@ name: Integration tests
on:
workflow_call:

env:
# Pull and tag images straight from Docker Hub, never through registry.defectdojo.com:
# the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI
# pulls must not count as installs.
DD_IMAGE_REGISTRY: docker.io

jobs:
integration_tests:
# run tests with docker compose
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/performance-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@ name: Performance Tests
on:
workflow_call:

env:
# Pull and tag images straight from Docker Hub, never through registry.defectdojo.com:
# the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI
# pulls must not count as installs.
DD_IMAGE_REGISTRY: docker.io

jobs:
performance-tests:
name: Performance Tests
Expand Down
6 changes: 6 additions & 0 deletions .github/workflows/rest-framework-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,12 @@ on:
type: boolean
default: false

env:
# Pull and tag images straight from Docker Hub, never through registry.defectdojo.com:
# the images CI built itself are tagged defectdojo/... (= docker.io/defectdojo/...), and CI
# pulls must not count as installs.
DD_IMAGE_REGISTRY: docker.io

jobs:
unit_tests:
name: Rest Framework Unit Tests
Expand Down
10 changes: 5 additions & 5 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ services:
build:
context: ./
dockerfile: "Dockerfile.nginx-alpine"
image: "defectdojo/defectdojo-nginx:${NGINX_VERSION:-latest}"
image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-nginx:${NGINX_VERSION:-latest}"
depends_on:
uwsgi:
condition: service_started
Expand All @@ -35,7 +35,7 @@ services:
context: ./
dockerfile: "Dockerfile.django-${DEFECT_DOJO_OS:-debian}"
target: release
image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
depends_on:
initializer:
condition: service_completed_successfully
Expand All @@ -60,7 +60,7 @@ services:
target: /app/docker/extra_settings
- "defectdojo_media:${DD_MEDIA_ROOT:-/app/media}"
celerybeat:
image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
depends_on:
initializer:
condition: service_completed_successfully
Expand All @@ -81,7 +81,7 @@ services:
source: ./docker/extra_settings
target: /app/docker/extra_settings
celeryworker:
image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
depends_on:
initializer:
condition: service_completed_successfully
Expand All @@ -103,7 +103,7 @@ services:
target: /app/docker/extra_settings
- "defectdojo_media:${DD_MEDIA_ROOT:-/app/media}"
initializer:
image: "defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
image: "${DD_IMAGE_REGISTRY:-registry.defectdojo.com}/defectdojo/defectdojo-django:${DJANGO_VERSION:-latest}"
depends_on:
postgres:
condition: service_started
Expand Down
17 changes: 16 additions & 1 deletion readme-docs/DOCKER.md
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ docker compose build nginx
> **_NOTE:_** It's possible to add extra fixtures in folder "/docker/extra_fixtures".

## Run with Docker Compose in release mode
To run the application based on previously built image (or based on dockerhub images if none was locally built), run:
To run the application based on previously built image (or based on the published images if none was locally built, see [Image registry](#image-registry)), run:

```zsh
docker/setEnv.sh release
Expand Down Expand Up @@ -227,6 +227,21 @@ aedc404d6dee defectdojo/defectdojo-nginx:1.0.0 "/entrypoint-nginx.sh"
...
```

## Image registry
`docker-compose.yml` pulls the DefectDojo images through `registry.defectdojo.com`. It redirects every
request to the same images on Docker Hub (`hub.docker.com/u/defectdojo`); no image is stored or changed
there. Each pull is logged (time, image, tag, client and the requesting network) so the project can see where
DefectDojo is installed.

To pull straight from Docker Hub, or from your own mirror, set `DD_IMAGE_REGISTRY` before running Docker Compose:

```zsh
export DD_IMAGE_REGISTRY=docker.io # Docker Hub
export DD_IMAGE_REGISTRY=mirror.example.com # or your own registry mirror
```

Images you build locally are tagged with the same name, so building and running works the same either way.

## Clean up Docker Compose

Removes all containers
Expand Down
Loading