collin/anvil
67ea942a2c65c09e0db51ba895c7e18443306af7 / Dockerfile
| 1 | # Multi-stage build for anvil. |
| 2 | # |
| 3 | # anvil is self-contained at runtime: SQLite (rusqlite) and the SSH crypto |
| 4 | # (aws-lc-rs, via russh) compile into the binary, and gix is pure-Rust — so the |
| 5 | # runtime image needs no git, no OpenSSH, and no system sqlite. |
| 6 | |
| 7 | # ---- build stage ---- |
| 8 | FROM rust:1.95-bookworm AS build |
| 9 | |
| 10 | # aws-lc-sys (russh crypto) needs cmake; rusqlite "bundled" needs a C compiler |
| 11 | # (present in the full rust image). perl is used by the aws-lc build scripts. |
| 12 | RUN apt-get update \ |
| 13 | && apt-get install -y --no-install-recommends cmake clang perl \ |
| 14 | && rm -rf /var/lib/apt/lists/* |
| 15 | |
| 16 | WORKDIR /src |
| 17 | COPY . . |
| 18 | RUN cargo build --release --bin anvild |
| 19 | |
| 20 | # ---- runtime stage ---- |
| 21 | FROM debian:bookworm-slim |
| 22 | |
| 23 | RUN apt-get update \ |
| 24 | && apt-get install -y --no-install-recommends ca-certificates \ |
| 25 | && rm -rf /var/lib/apt/lists/* \ |
| 26 | && useradd --system --user-group --home-dir /data anvil \ |
| 27 | && mkdir -p /data /etc/anvil \ |
| 28 | && chown -R anvil:anvil /data |
| 29 | |
| 30 | COPY --from=build /src/target/release/anvild /usr/local/bin/anvild |
| 31 | COPY deploy/anvil.toml /etc/anvil/anvil.toml |
| 32 | |
| 33 | # Web (proxied by Caddy over the internal network) and SSH (published to host). |
| 34 | EXPOSE 3000 2222 |
| 35 | VOLUME /data |
| 36 | USER anvil |
| 37 | |
| 38 | ENTRYPOINT ["/usr/local/bin/anvild"] |
| 39 | CMD ["-c", "/etc/anvil/anvil.toml", "serve"] |