anvilsign in

collin/anvil

1# anvil runtime image — just the prebuilt binary, no compilation in Docker.
2#
3# The binary is cross-compiled on the build host into a fully static
4# x86_64-musl executable (see deploy/build.sh: `cargo zigbuild --target
5# x86_64-unknown-linux-musl`), then staged at deploy/anvild and copied in here.
6# So building this image is a fast `COPY` — no QEMU-emulated release build, and
7# the VPS never compiles anything.
8
9FROM debian:bookworm-slim
10
11# No git in the image: anvil is pure gitoxide (see CLAUDE.md), including the
12# push-mirroring client.
13RUN apt-get update \
14 && apt-get install -y --no-install-recommends ca-certificates \
15 && rm -rf /var/lib/apt/lists/* \
16 && useradd --system --user-group --home-dir /data anvil \
17 && mkdir -p /data /etc/anvil \
18 && chown -R anvil:anvil /data
19
20# Prebuilt static binary staged by deploy/build.sh.
21COPY deploy/anvild /usr/local/bin/anvild
22
23# Which baked config to ship: production's by default, the committed local one
24# when deploy/dev.sh builds the image.
25ARG CONFIG=deploy/anvil.toml
26COPY ${CONFIG} /etc/anvil/anvil.toml
27
28EXPOSE 3000 2222
29VOLUME /data
30USER anvil
31
32ENTRYPOINT ["/usr/local/bin/anvild"]
33CMD ["-c", "/etc/anvil/anvil.toml", "serve"]