Containerfile
| 1 | # Which stage supplies the binary: "build" compiles it, "prebuilt" takes it |
| 2 | # from ci-bin/ (see below). Declared before the first FROM so the stage lookup |
| 3 | # in COPY --from can resolve it. |
| 4 | ARG BIN_STAGE=build |
| 5 | |
| 6 | FROM golang:1.26-alpine AS build |
| 7 | |
| 8 | WORKDIR /build |
| 9 | COPY go.mod go.sum ./ |
| 10 | RUN go mod download |
| 11 | |
| 12 | COPY . . |
| 13 | RUN CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o /vidarchive ./cmd/vidarchive |
| 14 | |
| 15 | # ── prebuilt ───────────────────────────────────────────────────────────────── |
| 16 | # CI has the binary already. It puts it at ci-bin/vidarchive and selects this |
| 17 | # stage with --build-arg BIN_STAGE=prebuilt. BuildKit and buildah do not build a |
| 18 | # stage nobody references, so a normal build needs no ci-bin/. |
| 19 | FROM scratch AS prebuilt |
| 20 | COPY ci-bin/vidarchive /vidarchive |
| 21 | |
| 22 | # ── runtime ────────────────────────────────────────────────────────────────── |
| 23 | # Debian, not Alpine: the deno JS runtime ships glibc builds only. VidArchive |
| 24 | # downloads yt-dlp and deno into /data/bin at first start, so no Python here. |
| 25 | FROM debian:trixie-slim |
| 26 | |
| 27 | # re-declare: args set before FROM do not carry into stages |
| 28 | ARG BIN_STAGE |
| 29 | |
| 30 | RUN apt-get update \ |
| 31 | && apt-get install -y --no-install-recommends ca-certificates ffmpeg curl \ |
| 32 | && rm -rf /var/lib/apt/lists/* |
| 33 | |
| 34 | WORKDIR /app |
| 35 | |
| 36 | # Templates and static files are embedded in the binary (assets.go). |
| 37 | COPY --from=${BIN_STAGE} /vidarchive /app/vidarchive |
| 38 | |
| 39 | ENV VIDARCHIVE_DATA_DIR=/data |
| 40 | ENV VIDARCHIVE_PORT=8080 |
| 41 | |
| 42 | VOLUME ["/data"] |
| 43 | |
| 44 | EXPOSE 8080 |
| 45 | |
| 46 | # /healthz reports 503 when the database is unreachable. start-period covers |
| 47 | # migrations and the first yt-dlp download so they don't count as failures. |
| 48 | HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \ |
| 49 | CMD curl -fsS -o /dev/null "http://127.0.0.1:${VIDARCHIVE_PORT}/healthz" || exit 1 |
| 50 | |
| 51 | # exec form, so the app is PID 1 and gets SIGTERM directly — it needs that for a |
| 52 | # graceful shutdown (drain requests, kill yt-dlp children, checkpoint the DB). |
| 53 | ENTRYPOINT ["/app/vidarchive"] |
| 54 |