Publish only the distroless Flood runtime as latest
This commit is contained in:
1 parent
66e87558ce
commit
b1657c3b61
7 files changed
+59
-253
No files matched your search
+21
-49
@@ -1,55 +1,27 @@
|
||||
# Flood UI only: connects to an external torrent service. No bundled rTorrent.
|
||||
# Build from a clean upstream release checkout using the Gitea workflow.
|
||||
|
||||
ARG BUILDPLATFORM=amd64
|
||||
# Alpine-built binaries and musl stay together; no shell/package manager in final image.
|
||||
ARG NODE_IMAGE=docker.io/node:24.18.1-alpine3.24
|
||||
|
||||
FROM --platform=$BUILDPLATFORM ${NODE_IMAGE} as nodebuild
|
||||
|
||||
WORKDIR /usr/src/app/
|
||||
|
||||
# Copy project files
|
||||
FROM ${NODE_IMAGE} AS nodebuild
|
||||
WORKDIR /usr/src/app
|
||||
COPY . ./
|
||||
|
||||
# Use the package manager and lockfile declared by the upstream release.
|
||||
RUN npm install -g corepack && corepack enable && corepack install
|
||||
RUN pnpm install --frozen-lockfile
|
||||
|
||||
# Build Flood server and client assets.
|
||||
RUN npm install -g corepack && corepack enable && corepack install \
|
||||
&& pnpm install --frozen-lockfile
|
||||
RUN npm run build
|
||||
|
||||
# Now get the clean Node.js image
|
||||
FROM ${NODE_IMAGE} as flood
|
||||
FROM ${NODE_IMAGE} AS runtime
|
||||
RUN apk add --no-cache mediainfo coreutils ca-certificates tzdata \
|
||||
lddtreepax python3
|
||||
COPY .ci-runtime-root.py /build/runtime-root.py
|
||||
RUN python3 /build/runtime-root.py /runtime /usr/local/bin/node \
|
||||
/usr/bin/mediainfo "$(command -v df)"
|
||||
COPY --from=nodebuild /usr/src/app/dist /runtime/usr/src/app/dist
|
||||
COPY --from=nodebuild /usr/src/app/package.json /runtime/usr/src/app/package.json
|
||||
COPY --from=nodebuild /usr/src/app/LICENSE /runtime/usr/src/app/LICENSE
|
||||
|
||||
WORKDIR /usr/src/app/
|
||||
|
||||
# Copy sources
|
||||
COPY --from=nodebuild /usr/src/app ./
|
||||
|
||||
# Install runtime dependencies
|
||||
RUN apk --no-cache add \
|
||||
mediainfo
|
||||
|
||||
# Create "download" user
|
||||
# RUN adduser -h /home/download -s /sbin/nologin --disabled-password download
|
||||
|
||||
# Run as "download" user
|
||||
# USER download
|
||||
|
||||
# Expose port 3000 and 4200
|
||||
FROM scratch
|
||||
COPY --from=runtime /runtime/ /
|
||||
ENV NODE_ENV=production HOME=/root PATH=/usr/local/bin:/usr/bin:/bin
|
||||
WORKDIR /usr/src/app
|
||||
RUN --mount=type=bind,from=nodebuild,source=/usr/src/app/.ci-startup.cjs,target=/ci-startup.cjs ["/usr/local/bin/node", "/ci-startup.cjs"]
|
||||
VOLUME ["/server/db"]
|
||||
EXPOSE 3000
|
||||
EXPOSE 4200
|
||||
|
||||
# Creating mountpoint for config
|
||||
RUN mkdir -p /server/db/
|
||||
RUN apk update
|
||||
RUN apk add coreutils
|
||||
|
||||
# System local configuration
|
||||
VOLUME /server/db/
|
||||
|
||||
# Fail the build before publication if the actual server cannot start.
|
||||
RUN node .ci-startup.cjs && rm .ci-startup.cjs
|
||||
|
||||
# Start Flood only, using the upstream v4.16.2 production entrypoint.
|
||||
ENTRYPOINT ["npm", "--prefix=/usr/src/app/", "run", "start", "--", "--host=0.0.0.0", "--rundir=/server/"]
|
||||
ENTRYPOINT ["/usr/local/bin/node", "--enable-source-maps", "--use_strict", "dist/index.js", "--host=0.0.0.0", "--rundir=/server/"]
|
||||
Reference in new issue
Block a user