Publish only the distroless Flood runtime as latest

This commit is contained in:
Ketan Patel committed 2026-10-03 00:06:02 -04:00
1 parent 66e87558ce
commit b1657c3b61
7 files changed
+59 -253

No files matched your search

+28 -45
View File
@@ -1,55 +1,38 @@
# docker-flood-client
Flood client image. Source: https://git.k2patel.in/k2patel/docker-flood-client
Source: https://git.k2patel.in/k2patel/docker-flood-client
Public access is read-only; account registration on this server is disabled.
Report issues at https://github.com/k2patel/docker-flood-client/issues.
For contributions, open an issue with a link to your branch or patch on another
Git provider. Changes are reviewed and applied by the maintainer on Gitea.
`docker.io/k2patel/floodui:latest` is the only maintained image variant and is
an Alpine/musl distroless runtime. The separate `:distroless` tag is retired.
It runs the Flood web UI/API and connects to an external torrent service;
it does not bundle or start rTorrent.
Gitea Actions publishes `docker.io/k2patel/floodui:latest` only on manual runs.
Select `main` in Actions → Build and Push Custom Flood Image → Run workflow
and set the required `flood_version` release tag. The configured release is
`v4.16.2`. Repository pushes do not trigger builds.
## Build and publication
This is a Flood-only image using the custom `Dockerfile.client`: it runs the
Flood web UI/API and connects to an external torrent service. It does not bundle
or start rTorrent. The Dockerfile uses the upstream pnpm lockfile and builds the server and client
assets; changing release families may require updating the build tooling.
Gitea Actions publishes only on manual runs. Select `main` in Actions →
**Build and Push Distroless Flood** → Run workflow and set the required
`flood_version` release tag (default `v4.16.2`). Pushes do not trigger builds.
The upstream pnpm lockfile builds the server and UI; switching release families
may require changes to the build tooling.
Set Actions secrets `DOCKER_USERNAME` and `DOCKER_TOKEN` with Docker Hub write
access to `k2patel/floodui`. Builds run remotely on the Kubernetes runner for
`linux/amd64`, pushing directly to Docker Hub. Images are not loaded into the
runner image store, and the temporary builder and cache are removed afterward.
No image archives or build records are uploaded to Gitea, and no local container
builds are required.
The workflow uses `Dockerfile.client`, Node 24.18.1 on Alpine 3.24, and a scratch
final image. It includes Node, the bundled server/UI, mediainfo, GNU df, their
musl libraries, CA certificates and timezone data. There is no shell, npm/pnpm,
package manager, source tree, node_modules or compiler in the runtime.
Node starts directly with `--host=0.0.0.0 --rundir=/server/`.
Base image: Node.js 24.18.1 on Alpine Linux 3.24 stable (`node:24.18.1-alpine3.24`),
with the Alpine stable series explicitly selected.
CI starts Flood in the stripped filesystem and requires HTTP 200, working
mediainfo/df, and absence of shell/package-manager binaries before publication.
Builds use the Kubernetes runner for `linux/amd64`, pushing directly to Docker
Hub; temporary builders and caches are removed afterward. Configure Actions
secrets `DOCKER_USERNAME` and `DOCKER_TOKEN` with write access to `k2patel/floodui`.
The image build starts the actual Flood server and requires HTTP 200 before
publishing; it does not start a torrent daemon.
## Updating an existing deployment
The entrypoint uses `npm run start`, matching upstream v4.16.2, while retaining
`--host=0.0.0.0` and `--rundir=/server/`. The upstream combined rTorrent stage
is deliberately excluded.
Use `k2patel/floodui:latest`, pull, and recreate the service. Keep existing
connection settings and mounts. Root UID, port 3000 and `/server/db` are unchanged.
The default Compose file in docker-rtorrent uses distroless `:latest` for both
services and supplies rTorrent's native health check; no overlay is needed.
## Distroless variant
The manual **Build Distroless Flood** workflow publishes `k2patel/floodui:distroless`
for the selected Flood release (default `v4.16.2`). It does not change `latest`.
The Alpine 3.24-derived runtime contains Node 24.18.1, the bundled Flood server/UI,
mediainfo, GNU df, their musl libraries, CA certificates and timezone data. The
final image is built from scratch, with no shell, npm/pnpm, package manager,
node_modules, source tree or build tools. It starts Node directly and remains
separate from rTorrent. Root UID, port 3000, and `/server/db` stay compatible.
Before publication, CI starts Flood inside the exact stripped filesystem and
requires an HTTP 200 response; it also checks mediainfo and df can execute and
that shell/package-manager binaries are absent. All builds run remotely, and
the temporary builder/cache is removed afterward.
Change only the Compose image tag to `k2patel/floodui:distroless`; keep existing
mounts and connection settings. Revert to `latest` to roll back. A matching
rTorrent Compose overlay is provided in the docker-rtorrent repository.
Public access is read-only; account registration is disabled. Maintainer-applied
contributions can be based on a branch or patch against the current Gitea source.