Containerfile
| 1 | ARG BIN_STAGE=build |
| 2 | |
| 3 | FROM docker.io/library/rust:1-trixie AS build |
| 4 | ARG TRUNK_VERSION=0.21.14 |
| 5 | RUN rustup target add wasm32-unknown-unknown \ |
| 6 | && curl -sSfL https://github.com/trunk-rs/trunk/releases/download/v${TRUNK_VERSION}/trunk-x86_64-unknown-linux-gnu.tar.gz \ |
| 7 | | tar -xz -C /usr/local/bin |
| 8 | WORKDIR /src |
| 9 | COPY . . |
| 10 | RUN cd web && trunk build --release |
| 11 | RUN cargo build --release -p server |
| 12 | |
| 13 | # CI builds the server and web UI itself, puts them in ci-bin/ and selects this |
| 14 | # stage with --build-arg BIN_STAGE=prebuilt. An unreferenced stage is not built. |
| 15 | FROM scratch AS prebuilt |
| 16 | COPY ci-bin/otserver /src/target/release/otserver |
| 17 | COPY ci-bin/web /src/web/dist |
| 18 | |
| 19 | FROM ${BIN_STAGE} AS bin |
| 20 | |
| 21 | FROM docker.io/library/debian:trixie-slim |
| 22 | # webauthn-rs links OpenSSL. |
| 23 | RUN apt-get update && apt-get install -y --no-install-recommends libssl3t64 && rm -rf /var/lib/apt/lists/* \ |
| 24 | && useradd --system --uid 10001 ot && mkdir /data && chown ot /data |
| 25 | COPY --from=bin /src/target/release/otserver /usr/local/bin/ |
| 26 | COPY --from=bin /src/web/dist /srv/web |
| 27 | ENV OT_ADDR=0.0.0.0:8080 OT_DB=/data/ot.db OT_WEB_DIR=/srv/web |
| 28 | USER ot |
| 29 | VOLUME /data |
| 30 | EXPOSE 8080 |
| 31 | ENTRYPOINT ["otserver"] |
| 32 |