diff --git a/.gitea/workflows/redhat_build.yml b/.gitea/workflows/redhat_build.yml index c9ecba6..43a72f7 100644 --- a/.gitea/workflows/redhat_build.yml +++ b/.gitea/workflows/redhat_build.yml @@ -86,26 +86,26 @@ jobs: run: | sudo apt-get update && sudo apt-get install -y buildah fuse-overlayfs - # 5. Image direkt mit Buildah bauen (erzwingt --isolation chroot) + # 5. Image direkt mit Buildah bauen (nutzt Bash-Array gegen Word-Splitting) - name: Build Image with Buildah run: | # Systemweite Containers-Konfig auf chroot festlegen sudo mkdir -p /etc/containers printf '[containers]\nisolation = "chroot"\n' | sudo tee /etc/containers/containers.conf - # Metadata-Labels sauber in --label Argumente umwandeln - LABEL_FLAGS="" + # Metadata-Labels sauber in ein Bash-Array einlesen (schützt Leerzeichen) + BUILD_ARGS=() while IFS= read -r line; do if [ -n "$line" ]; then - LABEL_FLAGS="${LABEL_FLAGS} --label ${line}" + BUILD_ARGS+=("--label" "$line") fi done <<< "${{ steps.metadata.outputs.labels }}" - # Bildah mit explizitem --isolation chroot ausführen + # Buildah ausführen buildah bud \ --isolation chroot \ --format oci \ - ${LABEL_FLAGS} \ + "${BUILD_ARGS[@]}" \ -t "${{ env.IMAGE_NAME }}:${{ env.IMAGE_TAG }}" \ -f ./Containerfile .