build: package the server as an OCI container image

This commit is contained in:
randogoth 2026-10-06 10:27:46 +03:00
parent 088e860cad
commit 36faa4fb93
3 changed files with 72 additions and 0 deletions

6
.dockerignore Normal file
View file

@ -0,0 +1,6 @@
/target
/result
/result-*
.git
.jj
.devbox

29
Dockerfile Normal file
View file

@ -0,0 +1,29 @@
# Multi-stage build: a slim Rust toolchain compiles the release binary, and a
# slim Debian runtime carries it with no toolchain. The default entrypoint
# serves the demo site from /srv/itsybitsy; mount a real server file and
# content roots over those paths to serve something else.
FROM rust:1.97-slim AS build
WORKDIR /src
COPY Cargo.toml Cargo.lock ./
COPY core core
COPY gemtext gemtext
COPY wap wap
COPY text text
COPY bin bin
# The demo config serves wml decks, which the `wml` feature adds to the wap
# format; the listeners the config names are validated against the registry.
RUN cargo build --release --locked --package itsybitsy --features wml
FROM debian:bookworm-slim
RUN useradd --uid 1000 --create-home itsybitsy
WORKDIR /srv/itsybitsy
COPY --from=build /src/target/release/itsybitsy /usr/local/bin/itsybitsy
# The container config binds 0.0.0.0, because a loopback bind would leave
# every published port unreachable from outside the container. --chmod keeps
# the file readable by the runtime user whatever the checkout's own modes are.
COPY --chmod=644 docker/itsybitsy.toml ./itsybitsy.toml
COPY content ./content
USER itsybitsy
EXPOSE 8080 3000 1900 1965 7070
ENTRYPOINT ["itsybitsy", "--config", "/srv/itsybitsy/itsybitsy.toml"]

37
docker/itsybitsy.toml Normal file
View file

@ -0,0 +1,37 @@
version = 1
[site.demo]
root = "./content"
hosts = ["localhost", "127.0.0.1"]
[listener.web]
protocol = "http"
bind = "0.0.0.0:8080"
formats = ["wml", "xhtmlmp", "html"]
default_site = "demo"
[listener.spartan]
protocol = "spartan"
bind = "0.0.0.0:3000"
formats = ["gemtext"]
default_site = "demo"
[listener.nex]
protocol = "nex"
bind = "0.0.0.0:1900"
formats = ["text"]
site = "demo"
# Plaintext: a TLS terminator in front of the container owns 1965 and forwards
# here, as it does when deployed bare.
[listener.gemini]
protocol = "gemini"
bind = "0.0.0.0:1965"
formats = ["gemtext"]
default_site = "demo"
[listener.gopher]
protocol = "gopher"
bind = "0.0.0.0:7070"
formats = ["text"]
site = "demo"