brewlog/Dockerfile
Niels Göttsch 423ddc7870
Some checks failed
Build & Publish / Check (push) Successful in 2m15s
Build & Publish / Build & Publish (push) Failing after 9s
ci: build image daemonless with Kaniko (no Docker)
Replace the docker buildx / build-push-action build job with Kaniko running as
the job container: it builds the Dockerfile from the git context and pushes to
the forge registry, with no Docker daemon, no buildx, and no privileged DinD.

Kaniko cannot handle BuildKit `RUN --mount=type=cache`, so drop the two cache
mounts on the cargo build layer (plain `cargo build` now). Document the pipeline
and this gotcha (plus the node20-only runner and full-github-URL action rules) in
the README so it isn't reintroduced.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-16 17:17:09 +02:00

72 lines
2.7 KiB
Docker

# syntax=docker/dockerfile:1
# Multi-stage Dockerfile for brewlog.
# Uses chisel to create a minimal Ubuntu rootfs for the runtime image.
# ---------------------------------------------------------------------------
# Builder — Ubuntu with Rust toolchain installed
# ---------------------------------------------------------------------------
FROM ubuntu:26.04 AS builder
ENV RUSTUP_HOME=/usr/local/rustup \
CARGO_HOME=/usr/local/cargo \
PATH=/usr/local/cargo/bin:${PATH}
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates \
build-essential \
pkg-config \
libssl-dev \
mold \
binutils \
curl \
&& rm -rf /var/lib/apt/lists/*
RUN curl -sSf https://sh.rustup.rs \
| sh -s -- -y --profile minimal --default-toolchain 1.94.1
# Install tailwindcss standalone (needed by build.rs)
RUN mkdir -p /usr/local/bin \
&& curl -sL https://github.com/tailwindlabs/tailwindcss/releases/latest/download/tailwindcss-linux-x64 \
-o /usr/local/bin/tailwindcss && chmod +x /usr/local/bin/tailwindcss
WORKDIR /app
COPY . .
# NB: no `RUN --mount=type=cache` here on purpose. The CI image builder is
# Kaniko (daemonless, no Docker/BuildKit), which does not support BuildKit cache
# mounts — it errors on them. Keep this RUN plain. See README "CI / build".
RUN cargo build --release --locked \
&& mkdir -p /out \
&& cp target/release/brewlog /out/brewlog
# ---------------------------------------------------------------------------
# Chisel — minimal Ubuntu rootfs
# ---------------------------------------------------------------------------
FROM ubuntu:26.04 AS chisel
ARG TARGETARCH=amd64
RUN apt-get update && apt-get install -y --no-install-recommends \
curl ca-certificates \
&& rm -rf /var/lib/apt/lists/*
RUN curl -sL "https://github.com/canonical/chisel/releases/download/v1.4.1/chisel_v1.4.1_linux_${TARGETARCH}.tar.gz" \
| tar xz -C /usr/local/bin
RUN mkdir /rootfs && chisel cut --root /rootfs \
base-files_base \
base-files_release-info \
base-passwd_data \
ca-certificates_data \
libgcc-s1_libs \
libc6_libs \
libssl3t64_libs \
openssl_bins
RUN useradd --root /rootfs -u 1000 -U -M -s /bin/false brewlog \
&& mkdir -p /rootfs/home/brewlog /rootfs/data \
&& chown 1000:1000 /rootfs/home/brewlog /rootfs/data
# ---------------------------------------------------------------------------
# Runtime — scratch with chisel rootfs
# ---------------------------------------------------------------------------
FROM scratch
COPY --from=chisel /rootfs /
COPY --from=builder /out/brewlog /usr/local/bin/brewlog
USER 1000:1000
ENTRYPOINT ["brewlog", "serve", "--database-url", "sqlite:///data/brewlog.db"]