- Serve the session WebSocket on `/` through axum (`Session::from_axum`) with a 1 MiB message limit - Add `/health` (checks the database) and a `server healthcheck` subcommand used by the Dockerfile HEALTHCHECK - Shut down on SIGTERM/Ctrl+C so container stops are immediate - Move per-connection handler registration into `register_handlers` Co-Authored-By: Claude Opus 5.5 <[email protected]>
46 lines
1.1 KiB
Docker
46 lines
1.1 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
FROM rust:1-slim-bookworm AS builder
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
pkg-config \
|
|
libssl-dev \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
COPY . .
|
|
|
|
# Cache mounts keep the registry and target dir between builds, so only
|
|
# changed crates recompile.
|
|
RUN --mount=type=cache,target=/usr/local/cargo/registry \
|
|
--mount=type=cache,target=/app/target \
|
|
cargo build --release --locked \
|
|
&& cp target/release/server /usr/local/bin/server
|
|
|
|
FROM debian:bookworm-slim
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
ca-certificates \
|
|
libssl3 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN useradd --system --uid 10001 saturn \
|
|
&& mkdir /data \
|
|
&& chown saturn /data
|
|
|
|
COPY --from=builder /usr/local/bin/server /usr/local/bin/server
|
|
|
|
USER saturn
|
|
WORKDIR /data
|
|
|
|
ENV BIND_ADDR=0.0.0.0:8080 \
|
|
DATABASE_URL=sqlite:///data/users.db?mode=rwc
|
|
|
|
EXPOSE 8080
|
|
VOLUME ["/data"]
|
|
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
|
CMD ["server", "healthcheck"]
|
|
|
|
CMD ["server"]
|