build: package the server as an OCI container image
This commit is contained in:
parent
088e860cad
commit
36faa4fb93
3 changed files with 72 additions and 0 deletions
6
.dockerignore
Normal file
6
.dockerignore
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
/target
|
||||
/result
|
||||
/result-*
|
||||
.git
|
||||
.jj
|
||||
.devbox
|
||||
29
Dockerfile
Normal file
29
Dockerfile
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
# Multi-stage build: a slim Rust toolchain compiles the release binary, and a
|
||||
# slim Debian runtime carries it with no toolchain. The default entrypoint
|
||||
# serves the demo site from /srv/itsybitsy; mount a real server file and
|
||||
# content roots over those paths to serve something else.
|
||||
|
||||
FROM rust:1.97-slim AS build
|
||||
WORKDIR /src
|
||||
COPY Cargo.toml Cargo.lock ./
|
||||
COPY core core
|
||||
COPY gemtext gemtext
|
||||
COPY wap wap
|
||||
COPY text text
|
||||
COPY bin bin
|
||||
# The demo config serves wml decks, which the `wml` feature adds to the wap
|
||||
# format; the listeners the config names are validated against the registry.
|
||||
RUN cargo build --release --locked --package itsybitsy --features wml
|
||||
|
||||
FROM debian:bookworm-slim
|
||||
RUN useradd --uid 1000 --create-home itsybitsy
|
||||
WORKDIR /srv/itsybitsy
|
||||
COPY --from=build /src/target/release/itsybitsy /usr/local/bin/itsybitsy
|
||||
# The container config binds 0.0.0.0, because a loopback bind would leave
|
||||
# every published port unreachable from outside the container. --chmod keeps
|
||||
# the file readable by the runtime user whatever the checkout's own modes are.
|
||||
COPY --chmod=644 docker/itsybitsy.toml ./itsybitsy.toml
|
||||
COPY content ./content
|
||||
USER itsybitsy
|
||||
EXPOSE 8080 3000 1900 1965 7070
|
||||
ENTRYPOINT ["itsybitsy", "--config", "/srv/itsybitsy/itsybitsy.toml"]
|
||||
37
docker/itsybitsy.toml
Normal file
37
docker/itsybitsy.toml
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
version = 1
|
||||
|
||||
[site.demo]
|
||||
root = "./content"
|
||||
hosts = ["localhost", "127.0.0.1"]
|
||||
|
||||
[listener.web]
|
||||
protocol = "http"
|
||||
bind = "0.0.0.0:8080"
|
||||
formats = ["wml", "xhtmlmp", "html"]
|
||||
default_site = "demo"
|
||||
|
||||
[listener.spartan]
|
||||
protocol = "spartan"
|
||||
bind = "0.0.0.0:3000"
|
||||
formats = ["gemtext"]
|
||||
default_site = "demo"
|
||||
|
||||
[listener.nex]
|
||||
protocol = "nex"
|
||||
bind = "0.0.0.0:1900"
|
||||
formats = ["text"]
|
||||
site = "demo"
|
||||
|
||||
# Plaintext: a TLS terminator in front of the container owns 1965 and forwards
|
||||
# here, as it does when deployed bare.
|
||||
[listener.gemini]
|
||||
protocol = "gemini"
|
||||
bind = "0.0.0.0:1965"
|
||||
formats = ["gemtext"]
|
||||
default_site = "demo"
|
||||
|
||||
[listener.gopher]
|
||||
protocol = "gopher"
|
||||
bind = "0.0.0.0:7070"
|
||||
formats = ["text"]
|
||||
site = "demo"
|
||||
Loading…
Add table
Add a link
Reference in a new issue