Containerfile
⎇
Raw
1# Which stage supplies the binary: "build" compiles it, "prebuilt" takes it
2# from ci-bin/ (see below). Declared before the first FROM so the stage lookup
3# in COPY --from can resolve it.
4ARG BIN_STAGE=build
5
6FROM golang:1.26-alpine AS build
7
8WORKDIR /build
9COPY go.mod go.sum ./
10RUN go mod download
11
12COPY . .
13RUN CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o /vidarchive ./cmd/vidarchive
14
15# ── prebuilt ─────────────────────────────────────────────────────────────────
16# CI has the binary already. It puts it at ci-bin/vidarchive and selects this
17# stage with --build-arg BIN_STAGE=prebuilt. BuildKit and buildah do not build a
18# stage nobody references, so a normal build needs no ci-bin/.
19FROM scratch AS prebuilt
20COPY ci-bin/vidarchive /vidarchive
21
22# ── runtime ──────────────────────────────────────────────────────────────────
23FROM alpine:3.24
24
25# re-declare: args set before FROM do not carry into stages
26ARG BIN_STAGE
27
28RUN apk --no-cache add ca-certificates ffmpeg python3 py3-pip \
29 && python3 -m venv /opt/ytdlp \
30 && /opt/ytdlp/bin/pip install --no-cache-dir --upgrade yt-dlp
31
32ENV PATH="/opt/ytdlp/bin:${PATH}"
33
34WORKDIR /app
35
36# Templates and static files are embedded in the binary (assets.go).
37COPY --from=${BIN_STAGE} /vidarchive /app/vidarchive
38
39ENV VIDARCHIVE_DATA_DIR=/data
40ENV VIDARCHIVE_PORT=8080
41
42VOLUME ["/data"]
43
44EXPOSE 8080
45
46# /healthz reports 503 when the database is unreachable. start-period covers
47# migrations on first boot so they don't count as failures.
48HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
49 CMD wget -q -O /dev/null "http://127.0.0.1:${VIDARCHIVE_PORT}/healthz" || exit 1
50
51# exec form, so the app is PID 1 and gets SIGTERM directly — it needs that for a
52# graceful shutdown (drain requests, kill yt-dlp children, checkpoint the DB).
53ENTRYPOINT ["/app/vidarchive"]
54