anvilsign in

collin/anvil

1# anvil runtime image — just the prebuilt binary, no compilation in Docker.
2#
3# The binary is cross-compiled on the build host into a fully static
4# x86_64-musl executable (see deploy/build.sh: `cargo zigbuild --target
5# x86_64-unknown-linux-musl`), then staged at deploy/anvild and copied in here.
6# So building this image is a fast `COPY` — no QEMU-emulated release build, and
7# the VPS never compiles anything.
8
9FROM debian:bookworm-slim
10
11# git is needed at runtime only for push mirroring (`git push --mirror`);
12# everything else speaks gix in-process.
13RUN apt-get update \
14 && apt-get install -y --no-install-recommends ca-certificates git \
15 && rm -rf /var/lib/apt/lists/* \
16 && useradd --system --user-group --home-dir /data anvil \
17 && mkdir -p /data /etc/anvil \
18 && chown -R anvil:anvil /data
19
20# Prebuilt static binary staged by deploy/build.sh.
21COPY deploy/anvild /usr/local/bin/anvild
22COPY deploy/anvil.toml /etc/anvil/anvil.toml
23
24EXPOSE 3000 2222
25VOLUME /data
26USER anvil
27
28ENTRYPOINT ["/usr/local/bin/anvild"]
29CMD ["-c", "/etc/anvil/anvil.toml", "serve"]