# syntax=docker/dockerfile:1.7 # irongit: server (axum + embedded Astro build) plus the static ig CLI, which # the server publishes to R2 for install.sh and `ig upgrade`. # docker build -t irongit . # ---- Frontend ----------------------------------------------------------------- FROM oven/bun:1.4 AS frontend WORKDIR /src/frontend COPY frontend/package.json frontend/bun.lock ./ RUN bun install --frozen-lockfile COPY frontend/ ./ # The backend's Rust templates use Tailwind classes too; the CSS build scans them. COPY backend/src /src/backend/src RUN bun run build # ---- Rust --------------------------------------------------------------------- FROM rust:1-trixie AS rust RUN apt-get update \ && apt-get install -y --no-install-recommends musl-tools \ && rm -rf /var/lib/apt/lists/* \ && rustup target add x86_64-unknown-linux-musl WORKDIR /src COPY Cargo.toml Cargo.lock ./ COPY backend/ backend/ COPY cli/ cli/ COPY shared/ shared/ COPY --from=frontend /src/frontend/dist frontend/dist # deploy.sh passes the CLI version (bumped automatically when cli/ or shared/ # change) and the server URL ig defaults to. Empty values fall back to the # crate version and to no built-in server. ARG IG_BUILD_VERSION="" ARG IG_DEFAULT_HOST="" # Cache mounts keep the registry and build artifacts between image builds; # the binaries are copied out of the cache within the same step. RUN --mount=type=cache,target=/usr/local/cargo/registry \ --mount=type=cache,target=/src/target \ cargo build --release --locked -p irongit --no-default-features \ && IG_BUILD_VERSION="$IG_BUILD_VERSION" IG_DEFAULT_HOST="$IG_DEFAULT_HOST" \ cargo build --release --locked -p ig --target x86_64-unknown-linux-musl \ && mkdir -p /out \ && cp target/release/irongit /out/irongit \ && cp target/x86_64-unknown-linux-musl/release/ig /out/ig # ---- Runtime ------------------------------------------------------------------ FROM debian:trixie-slim AS runtime # git serves every push, clone and page; postgresql-client (17) is for backups. RUN apt-get update \ && apt-get install -y --no-install-recommends ca-certificates git postgresql-client wget \ && rm -rf /var/lib/apt/lists/* \ && groupadd --system --gid 10001 irongit \ && useradd --system --uid 10001 --gid irongit --home-dir /data --no-create-home --shell /usr/sbin/nologin irongit \ && mkdir -p /data \ && chown irongit:irongit /data \ && chmod 0750 /data COPY --from=rust --chown=root:root --chmod=0755 /out/irongit /usr/local/bin/irongit COPY --from=rust --chown=root:root --chmod=0755 /out/ig /usr/local/share/irongit/ig USER irongit ENV HOST=0.0.0.0 \ PORT=7878 \ SSH_PORT=2222 \ DATA_DIR=/data \ HOME=/data \ MALLOC_ARENA_MAX=2 \ RUST_LOG=info EXPOSE 7878 2222 VOLUME ["/data"] HEALTHCHECK --interval=10s --timeout=5s --start-period=20s --retries=6 \ CMD wget -q -O /dev/null http://127.0.0.1:7878/api/health || exit 1 ENTRYPOINT ["/usr/local/bin/irongit"] CMD ["serve"]