# Which stage supplies the binary: "build" compiles it, "prebuilt" takes it # from ci-bin/ (see below). Declared before the first FROM so the stage lookup # in COPY --from can resolve it. ARG BIN_STAGE=build FROM golang:1.26-alpine AS build WORKDIR /build COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o /vidarchive ./cmd/vidarchive # ── prebuilt ───────────────────────────────────────────────────────────────── # CI has the binary already. It puts it at ci-bin/vidarchive and selects this # stage with --build-arg BIN_STAGE=prebuilt. BuildKit and buildah do not build a # stage nobody references, so a normal build needs no ci-bin/. FROM scratch AS prebuilt COPY ci-bin/vidarchive /vidarchive # ── runtime ────────────────────────────────────────────────────────────────── FROM alpine:3.24 # re-declare: args set before FROM do not carry into stages ARG BIN_STAGE RUN apk --no-cache add ca-certificates ffmpeg python3 py3-pip \ && python3 -m venv /opt/ytdlp \ && /opt/ytdlp/bin/pip install --no-cache-dir --upgrade yt-dlp ENV PATH="/opt/ytdlp/bin:${PATH}" WORKDIR /app # Templates and static files are embedded in the binary (assets.go). COPY --from=${BIN_STAGE} /vidarchive /app/vidarchive ENV VIDARCHIVE_DATA_DIR=/data ENV VIDARCHIVE_PORT=8080 VOLUME ["/data"] EXPOSE 8080 # /healthz reports 503 when the database is unreachable. start-period covers # migrations on first boot so they don't count as failures. HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \ CMD wget -q -O /dev/null "http://127.0.0.1:${VIDARCHIVE_PORT}/healthz" || exit 1 # exec form, so the app is PID 1 and gets SIGTERM directly — it needs that for a # graceful shutdown (drain requests, kill yt-dlp children, checkpoint the DB). ENTRYPOINT ["/app/vidarchive"]