anvilsign in

collin/anvil

1# Multi-stage build for anvil.
2#
3# anvil is self-contained at runtime: SQLite (rusqlite) and the SSH crypto
4# (aws-lc-rs, via russh) compile into the binary, and gix is pure-Rust — so the
5# runtime image needs no git, no OpenSSH, and no system sqlite.
6
7# ---- build stage ----
8FROM rust:1.95-bookworm AS build
9
10# aws-lc-sys (russh crypto) needs cmake; rusqlite "bundled" needs a C compiler
11# (present in the full rust image). perl is used by the aws-lc build scripts.
12RUN apt-get update \
13 && apt-get install -y --no-install-recommends cmake clang perl \
14 && rm -rf /var/lib/apt/lists/*
15
16WORKDIR /src
17COPY . .
18RUN cargo build --release --bin anvild
19
20# ---- runtime stage ----
21FROM debian:bookworm-slim
22
23RUN apt-get update \
24 && apt-get install -y --no-install-recommends ca-certificates \
25 && rm -rf /var/lib/apt/lists/* \
26 && useradd --system --user-group --home-dir /data anvil \
27 && mkdir -p /data /etc/anvil \
28 && chown -R anvil:anvil /data
29
30COPY --from=build /src/target/release/anvild /usr/local/bin/anvild
31COPY deploy/anvil.toml /etc/anvil/anvil.toml
32
33# Web (proxied by Caddy over the internal network) and SSH (published to host).
34EXPOSE 3000 2222
35VOLUME /data
36USER anvil
37
38ENTRYPOINT ["/usr/local/bin/anvild"]
39CMD ["-c", "/etc/anvil/anvil.toml", "serve"]