anvilsign in

collin/anvil

1# anvil runtime image — just the prebuilt binary, no compilation in Docker.
2#
3# The binary is cross-compiled on the build host into a fully static
4# x86_64-musl executable (see deploy/build.sh: `cargo zigbuild --target
5# x86_64-unknown-linux-musl`), then staged at deploy/anvild and copied in here.
6# So building this image is a fast `COPY` — no QEMU-emulated release build, and
7# the VPS never compiles anything.
8
9FROM debian:bookworm-slim
10
11RUN apt-get update \
12 && apt-get install -y --no-install-recommends ca-certificates \
13 && rm -rf /var/lib/apt/lists/* \
14 && useradd --system --user-group --home-dir /data anvil \
15 && mkdir -p /data /etc/anvil \
16 && chown -R anvil:anvil /data
17
18# Prebuilt static binary staged by deploy/build.sh.
19COPY deploy/anvild /usr/local/bin/anvild
20COPY deploy/anvil.toml /etc/anvil/anvil.toml
21
22EXPOSE 3000 2222
23VOLUME /data
24USER anvil
25
26ENTRYPOINT ["/usr/local/bin/anvild"]
27CMD ["-c", "/etc/anvil/anvil.toml", "serve"]