- Read bind address and database URL from BIND_ADDR / DATABASE_URL
(defaults unchanged for local cargo run)
- Rename DockerFile to Dockerfile and rewrite it: current Rust for
edition 2024, BuildKit cache mounts, non-root user, DB on /data
- Add compose.yaml publishing ${HOST_PORT:-8080} with a persistent
data volume, and a .dockerignore
Co-Authored-By: Claude Opus 5.5 <[email protected]>
43 lines
995 B
Docker
43 lines
995 B
Docker
# syntax=docker/dockerfile:1
|
|
|
|
FROM rust:1-slim-bookworm AS builder
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
pkg-config \
|
|
libssl-dev \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
COPY . .
|
|
|
|
# Cache mounts keep the registry and target dir between builds, so only
|
|
# changed crates recompile.
|
|
RUN --mount=type=cache,target=/usr/local/cargo/registry \
|
|
--mount=type=cache,target=/app/target \
|
|
cargo build --release --locked \
|
|
&& cp target/release/server /usr/local/bin/server
|
|
|
|
FROM debian:bookworm-slim
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
ca-certificates \
|
|
libssl3 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN useradd --system --uid 10001 saturn \
|
|
&& mkdir /data \
|
|
&& chown saturn /data
|
|
|
|
COPY --from=builder /usr/local/bin/server /usr/local/bin/server
|
|
|
|
USER saturn
|
|
WORKDIR /data
|
|
|
|
ENV BIND_ADDR=0.0.0.0:8080 \
|
|
DATABASE_URL=sqlite:///data/users.db?mode=rwc
|
|
|
|
EXPOSE 8080
|
|
VOLUME ["/data"]
|
|
|
|
CMD ["server"]
|