-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
143 lines (111 loc) · 4.52 KB
/
Copy pathDockerfile
File metadata and controls
143 lines (111 loc) · 4.52 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
# Find eligible builder and runner images on Docker Hub. We use Ubuntu/Debian
# instead of Alpine to avoid DNS resolution issues in production.
#
# https://hub.docker.com/r/hexpm/elixir/tags?name=ubuntu
# https://hub.docker.com/_/ubuntu/tags
#
# This file is based on these images:
#
# - https://hub.docker.com/r/hexpm/elixir/tags - for the build image
# - https://hub.docker.com/_/debian/tags?name=bookworm-20251020-slim - for the release image
# - https://pkgs.org/ - resource for finding needed packages
# - Ex: docker.io/hexpm/elixir:1.17.3-erlang-26.2.4-debian-bookworm-20251020-slim
#
ARG ELIXIR_VERSION=1.17.3
ARG OTP_VERSION=26.2.4
ARG DEBIAN_VERSION=bookworm-20251020-slim
ARG BUILDER_IMAGE="docker.io/hexpm/elixir:${ELIXIR_VERSION}-erlang-${OTP_VERSION}-debian-${DEBIAN_VERSION}"
ARG RUNNER_IMAGE="docker.io/debian:${DEBIAN_VERSION}"
FROM ${BUILDER_IMAGE} AS builder
# install build dependencies (including Node.js for npm, brotli for compression, and Rust for NIFs)
RUN apt-get update \
&& apt-get install -y --no-install-recommends build-essential git curl brotli \
&& curl -fsSL https://deb.nodesource.com/setup_20.x | bash - \
&& apt-get install -y nodejs \
&& rm -rf /var/lib/apt/lists/*
# Install Rust for building NIFs from source (ex_keccak, ex_secp256k1)
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
ENV PATH="/root/.cargo/bin:${PATH}"
# Force building Rust NIFs from source (GitHub release assets often blocked from CI)
ENV EX_KECCAK_BUILD="1"
ENV RUSTLER_BUILD="1"
ENV AUTUMN_BUILD="1"
ENV MDEX_BUILD="1"
ENV LUMIS_BUILD="1"
ENV RESVG_BUILD="1"
# resvg's crate pins lto=true and codegen-units=1, which costs several minutes
# on a shared builder for no runtime benefit at this image size.
ENV CARGO_PROFILE_RELEASE_LTO="off"
ENV CARGO_PROFILE_RELEASE_CODEGEN_UNITS="16"
# prepare build dir
WORKDIR /app
# install hex + rebar
RUN mix local.hex --force \
&& mix local.rebar --force
# set build ENV
ENV MIX_ENV="prod"
# install mix dependencies
COPY mix.exs mix.lock ./
RUN mix deps.get --only $MIX_ENV
RUN mkdir config
# copy compile-time config files before we compile dependencies
# to ensure any relevant config change will trigger the dependencies
# to be re-compiled.
COPY config/config.exs config/${MIX_ENV}.exs config/
RUN mix deps.compile
# Copy package files for npm dependency installation (better Docker layer caching)
COPY assets/package.json assets/package-lock.json ./assets/
# Install npm dependencies (requires package.json, package-lock.json)
RUN mix assets.setup
# Copy rest of assets after npm install
COPY assets ./assets
COPY priv priv
COPY lib lib
# Compile the release
RUN mix compile
# compile assets
RUN mix assets.deploy
# Changes to config/runtime.exs don't require recompiling the code
COPY config/runtime.exs config/
COPY rel rel
RUN mix release
# start a new build stage so that the final image will only contain
# the compiled release and other runtime necessities
FROM ${RUNNER_IMAGE} AS final
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
libstdc++6 openssl libncurses5 locales ca-certificates \
chromium chromium-sandbox \
poppler-utils \
iptables iproute2 wget \
&& rm -rf /var/lib/apt/lists/*
# Install Tailscale (TUN mode reaches MinIO at 100.117.205.87 on the tailnet)
ARG TAILSCALE_VERSION=1.98.3
RUN wget --quiet "https://pkgs.tailscale.com/stable/tailscale_${TAILSCALE_VERSION}_amd64.tgz" -O /tmp/ts.tgz \
&& tar xzf /tmp/ts.tgz -C /usr/local/bin --strip-components=1 \
"tailscale_${TAILSCALE_VERSION}_amd64/tailscale" \
"tailscale_${TAILSCALE_VERSION}_amd64/tailscaled" \
&& rm /tmp/ts.tgz \
&& mkdir -p /var/run/tailscale /var/cache/tailscale /var/lib/tailscale
# Set the locale
RUN sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen \
&& locale-gen
ENV LANG=en_US.UTF-8
ENV LANGUAGE=en_US:en
ENV LC_ALL=en_US.UTF-8
WORKDIR "/app"
RUN chown nobody /app
# set runner ENV
ENV MIX_ENV="prod"
# Only copy the final release from the build stage
COPY --from=builder /app/_build/${MIX_ENV}/rel/droodotfoo ./
# Copy Fly entrypoint (starts tailscaled before the app)
COPY rel/start-fly.sh /app/start-fly.sh
RUN chmod +x /app/start-fly.sh
# Run as root so tailscaled can manage TUN/iptables. Fly's container
# isolation handles the security boundary.
# If using an environment that doesn't automatically reap zombie processes, it is
# advised to add an init process such as tini via `apt-get install`
# above and adding an entrypoint. See https://github.com/krallin/tini for details
# ENTRYPOINT ["/tini", "--"]
CMD ["/app/start-fly.sh"]