Repository navigation
Expand file tree
/
Copy pathDockerfile.dev-prod
More file actions
84 lines (69 loc) · 2.86 KB
/
Copy pathDockerfile.dev-prod
File metadata and controls
84 lines (69 loc) · 2.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
# syntax=docker/dockerfile:1
# The running container needs `--security-opt seccomp=unconfined` because its
# rootless service and development sandboxes launch nested gVisor processes.
FROM debian:trixie-slim AS builder
ARG DEBIAN_FRONTEND=noninteractive
ARG VERSION
ENV CGO_ENABLED=0 \
THE8020_NETWORK_MAIN_PORT=80 \
THE8020_NETWORK_SSH_PORT=22 \
THE8020_SANDBOX_RUNTIME_MODE=rootless \
THE8020_OUTER_CONTAINER_BUILD=true \
THE8020_SKIP_RUNTIME_HOST=true
RUN apt-get update \
&& apt-get install --yes --no-install-recommends \
bash \
bzip2 \
ca-certificates \
curl \
git \
python3 \
&& rm -rf /var/lib/apt/lists/*
COPY build-image.sh /usr/local/bin/build-image.sh
RUN chmod 0755 /usr/local/bin/build-image.sh \
&& /usr/local/bin/build-image.sh "$VERSION"
FROM debian:trixie-slim
ARG DEBIAN_FRONTEND=noninteractive
ARG VERSION
ENV THE8020_NETWORK_MAIN_PORT=80 \
THE8020_NETWORK_SSH_PORT=22 \
THE8020_SANDBOX_RUNTIME_MODE=rootless
LABEL org.opencontainers.image.source="https://github.com/the8020/deploy" \
org.opencontainers.image.version="$VERSION"
RUN apt-get update \
&& apt-get install --yes --no-install-recommends \
bash \
ca-certificates \
curl \
git \
&& rm -rf /var/lib/apt/lists/*
COPY --from=builder /usr/local/src/the8020/.development/bin/ /usr/local/bin/
COPY --from=builder /usr/local/src/the8020/docker/rootfs/ /
COPY --from=builder /usr/local/share/the8020/ /usr/local/share/the8020/
COPY --from=builder /8020/packages/ /8020/packages/
COPY --from=builder /8020/scripts/ /8020/scripts/
COPY --from=builder /8020/node/kernel/runtime/ /8020/node/kernel/runtime/
# Ship code and runtime assets, with fresh database, identities and keys per volume.
RUN install -d -m 0700 /8020/node/kernel /8020/database \
&& install -d -m 0755 /8020/users \
&& install -m 0600 /dev/null /8020/kernel.toml
# Restore runtime assets independently into both fresh instances at startup.
RUN grep -Fq 'INSTANCE_ROOT=${THE8020_INSTANCE_ROOT:-/8020}' /usr/local/bin/docker-entrypoint.sh \
&& test -f /usr/local/share/the8020/runtime-state/id \
&& kernel --root /8020-prod --init-defaults --init-only \
&& install -m 0600 /dev/null /8020-prod/kernel.toml \
&& for directory in packages scripts; do \
mkdir -p "/8020-prod/$directory" \
&& cp -a "/8020/$directory/." "/8020-prod/$directory/" || exit 1; \
done \
&& test -f /8020/packages/the8020/deployments/cbus/commands/connect.toml
COPY dev-prod.sh /usr/local/bin/dev-prod.sh
RUN chmod 0755 /usr/local/bin/dev-prod.sh
WORKDIR /8020
VOLUME ["/8020", "/8020-prod"]
EXPOSE 80/tcp 22/tcp 8080/tcp 2222/tcp
STOPSIGNAL SIGTERM
HEALTHCHECK --interval=30s --timeout=10s --start-period=120s --retries=3 \
CMD /usr/local/bin/dev-prod.sh health
ENTRYPOINT ["/usr/local/bin/dev-prod.sh"]
CMD ["serve"]