# Which stage supplies the binary: "build" compiles it, "prebuilt" takes it # from ci-bin/ (see below). Declared before the first FROM so the stage lookup # in COPY --from can resolve it. ARG BIN_STAGE=build FROM golang:1.26-alpine AS build WORKDIR /build COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o /vidarchive ./cmd/vidarchive # ── prebuilt ───────────────────────────────────────────────────────────────── # CI has the binary already. It puts it at ci-bin/vidarchive and selects this # stage with --build-arg BIN_STAGE=prebuilt. BuildKit and buildah do not build a # stage nobody references, so a normal build needs no ci-bin/. FROM scratch AS prebuilt COPY ci-bin/vidarchive /vidarchive # ── runtime ────────────────────────────────────────────────────────────────── # Debian, not Alpine: the deno JS runtime ships glibc builds only. VidArchive # downloads yt-dlp and deno into /data/bin at first start, so no Python here. FROM debian:trixie-slim # re-declare: args set before FROM do not carry into stages ARG BIN_STAGE RUN apt-get update \ && apt-get install -y --no-install-recommends ca-certificates ffmpeg curl \ && rm -rf /var/lib/apt/lists/* WORKDIR /app # Templates and static files are embedded in the binary (assets.go). COPY --from=${BIN_STAGE} /vidarchive /app/vidarchive ENV VIDARCHIVE_DATA_DIR=/data ENV VIDARCHIVE_PORT=8080 VOLUME ["/data"] EXPOSE 8080 # /healthz reports 503 when the database is unreachable. start-period covers # migrations and the first yt-dlp download so they don't count as failures. HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \ CMD curl -fsS -o /dev/null "http://127.0.0.1:${VIDARCHIVE_PORT}/healthz" || exit 1 # exec form, so the app is PID 1 and gets SIGTERM directly — it needs that for a # graceful shutdown (drain requests, kill yt-dlp children, checkpoint the DB). ENTRYPOINT ["/app/vidarchive"]