build: package the server as an OCI container image
This commit is contained in:
parent
088e860cad
commit
36faa4fb93
3 changed files with 72 additions and 0 deletions
29
Dockerfile
Normal file
29
Dockerfile
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
# Multi-stage build: a slim Rust toolchain compiles the release binary, and a
|
||||
# slim Debian runtime carries it with no toolchain. The default entrypoint
|
||||
# serves the demo site from /srv/itsybitsy; mount a real server file and
|
||||
# content roots over those paths to serve something else.
|
||||
|
||||
FROM rust:1.97-slim AS build
|
||||
WORKDIR /src
|
||||
COPY Cargo.toml Cargo.lock ./
|
||||
COPY core core
|
||||
COPY gemtext gemtext
|
||||
COPY wap wap
|
||||
COPY text text
|
||||
COPY bin bin
|
||||
# The demo config serves wml decks, which the `wml` feature adds to the wap
|
||||
# format; the listeners the config names are validated against the registry.
|
||||
RUN cargo build --release --locked --package itsybitsy --features wml
|
||||
|
||||
FROM debian:bookworm-slim
|
||||
RUN useradd --uid 1000 --create-home itsybitsy
|
||||
WORKDIR /srv/itsybitsy
|
||||
COPY --from=build /src/target/release/itsybitsy /usr/local/bin/itsybitsy
|
||||
# The container config binds 0.0.0.0, because a loopback bind would leave
|
||||
# every published port unreachable from outside the container. --chmod keeps
|
||||
# the file readable by the runtime user whatever the checkout's own modes are.
|
||||
COPY --chmod=644 docker/itsybitsy.toml ./itsybitsy.toml
|
||||
COPY content ./content
|
||||
USER itsybitsy
|
||||
EXPOSE 8080 3000 1900 1965 7070
|
||||
ENTRYPOINT ["itsybitsy", "--config", "/srv/itsybitsy/itsybitsy.toml"]
|
||||
Loading…
Add table
Add a link
Reference in a new issue