Publish only the distroless Flood runtime as latest

This commit is contained in:
Ketan Patel committed 2026-10-03 00:06:02 -04:00
1 parent 66e87558ce
commit b1657c3b61
7 files changed
+59 -253

No files matched your search

+21 -49
View File
@@ -1,55 +1,27 @@
# Flood UI only: connects to an external torrent service. No bundled rTorrent.
# Build from a clean upstream release checkout using the Gitea workflow.
ARG BUILDPLATFORM=amd64
# Alpine-built binaries and musl stay together; no shell/package manager in final image.
ARG NODE_IMAGE=docker.io/node:24.18.1-alpine3.24
FROM --platform=$BUILDPLATFORM ${NODE_IMAGE} as nodebuild
WORKDIR /usr/src/app/
# Copy project files
FROM ${NODE_IMAGE} AS nodebuild
WORKDIR /usr/src/app
COPY . ./
# Use the package manager and lockfile declared by the upstream release.
RUN npm install -g corepack && corepack enable && corepack install
RUN pnpm install --frozen-lockfile
# Build Flood server and client assets.
RUN npm install -g corepack && corepack enable && corepack install \
&& pnpm install --frozen-lockfile
RUN npm run build
# Now get the clean Node.js image
FROM ${NODE_IMAGE} as flood
FROM ${NODE_IMAGE} AS runtime
RUN apk add --no-cache mediainfo coreutils ca-certificates tzdata \
lddtreepax python3
COPY .ci-runtime-root.py /build/runtime-root.py
RUN python3 /build/runtime-root.py /runtime /usr/local/bin/node \
/usr/bin/mediainfo "$(command -v df)"
COPY --from=nodebuild /usr/src/app/dist /runtime/usr/src/app/dist
COPY --from=nodebuild /usr/src/app/package.json /runtime/usr/src/app/package.json
COPY --from=nodebuild /usr/src/app/LICENSE /runtime/usr/src/app/LICENSE
WORKDIR /usr/src/app/
# Copy sources
COPY --from=nodebuild /usr/src/app ./
# Install runtime dependencies
RUN apk --no-cache add \
mediainfo
# Create "download" user
# RUN adduser -h /home/download -s /sbin/nologin --disabled-password download
# Run as "download" user
# USER download
# Expose port 3000 and 4200
FROM scratch
COPY --from=runtime /runtime/ /
ENV NODE_ENV=production HOME=/root PATH=/usr/local/bin:/usr/bin:/bin
WORKDIR /usr/src/app
RUN --mount=type=bind,from=nodebuild,source=/usr/src/app/.ci-startup.cjs,target=/ci-startup.cjs ["/usr/local/bin/node", "/ci-startup.cjs"]
VOLUME ["/server/db"]
EXPOSE 3000
EXPOSE 4200
# Creating mountpoint for config
RUN mkdir -p /server/db/
RUN apk update
RUN apk add coreutils
# System local configuration
VOLUME /server/db/
# Fail the build before publication if the actual server cannot start.
RUN node .ci-startup.cjs && rm .ci-startup.cjs
# Start Flood only, using the upstream v4.16.2 production entrypoint.
ENTRYPOINT ["npm", "--prefix=/usr/src/app/", "run", "start", "--", "--host=0.0.0.0", "--rundir=/server/"]
ENTRYPOINT ["/usr/local/bin/node", "--enable-source-maps", "--use_strict", "dist/index.js", "--host=0.0.0.0", "--rundir=/server/"]