# Unified test image for all FIPS integration test harnesses. # # Supports multiple modes via FIPS_TEST_MODE environment variable: # default — static/basic: dnsmasq + sshd + iperf3 + http + fips # chaos — above + ethernet interface wait loop + TCP ECN # sidecar — config from env vars + iptables isolation + fips # tor-socks5 — dnsmasq + sshd + fips (tor daemon is separate container) # tor-directory — dnsmasq + tor (directory mode) + wait for .onion + fips FROM debian:trixie-slim RUN apt-get update && \ apt-get install -y --no-install-recommends \ iproute2 iputils-ping dnsutils \ openssh-client openssh-server \ dnsmasq iptables tor \ iperf3 curl python3 nftables conntrack \ tcpdump netcat-openbsd rsync && \ rm -rf /var/lib/apt/lists/* # SSH server with no authentication (test only!) RUN mkdir -p /var/run/sshd && \ ssh-keygen -A && \ sed -i 's/#PermitRootLogin prohibit-password/PermitRootLogin yes/' /etc/ssh/sshd_config && \ sed -i 's/#PermitEmptyPasswords no/PermitEmptyPasswords yes/' /etc/ssh/sshd_config && \ sed -i 's/UsePAM yes/UsePAM no/' /etc/ssh/sshd_config && \ passwd -d root # dnsmasq: forward .fips to FIPS daemon, everything else to Docker DNS RUN printf '%s\n' \ 'port=53' \ 'listen-address=127.0.0.1' \ 'bind-interfaces' \ 'server=/fips/::1#5354' \ 'server=127.0.0.11' \ 'no-resolv' \ >> /etc/dnsmasq.conf COPY fips fipsctl fipstop fips-gateway /usr/local/bin/ RUN chmod +x /usr/local/bin/fips /usr/local/bin/fipsctl /usr/local/bin/fipstop /usr/local/bin/fips-gateway # Mirror systemd's RuntimeDirectory=fips so the daemon's resolver picks # /run/fips/control.sock — matches production layout and the chaos sim # harness probe path (testing/chaos/sim/control.py). RUN mkdir -p /run/fips # Static web page for HTTP server (chaos/static modes) RUN printf 'Fuck IPs!\n' > /root/index.html COPY resolv.conf /etc/resolv.conf COPY entrypoint.sh /usr/local/bin/entrypoint.sh RUN chmod +x /usr/local/bin/entrypoint.sh ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]