Make distroless the sole latest image and default Compose runtime
Build and Push Docker Image / build (push) Successful in 53s
Build and Push Docker Image / build (push) Successful in 53s
This commit is contained in:
1 parent
8b88089cb4
commit
4b53923829
7 files changed
+45
-137
No files matched your search
@@ -24,26 +24,32 @@ are uploaded to Gitea, and no local container builds are required.
|
||||
# Latest 0.16 version caveat
|
||||
- since version 0.16 explicitly set `network.bind_address.set = 0.0.0.0`, when ipv6 is disabled on kernel.
|
||||
|
||||
## Distroless variant
|
||||
## Distroless runtime
|
||||
|
||||
`docker.io/k2patel/rtorrent:distroless` is built separately using the manual
|
||||
**Build Distroless rTorrent** workflow. It preserves the Alpine 3.24 rTorrent
|
||||
binary, musl libraries, CA certificates and timezone/terminal data in a `scratch`
|
||||
final image. It contains no shell, package manager, BusyBox, or build tools.
|
||||
A small native launcher removes the stale session lock and execs rTorrent,
|
||||
so signals go directly to rTorrent. It also provides the shell-free TCP healthcheck.
|
||||
`docker.io/k2patel/rtorrent:latest` is the only maintained image variant.
|
||||
The default Dockerfile exports the Alpine 3.24 rTorrent binary, musl libraries,
|
||||
CA certificates and timezone/terminal data into a `scratch` image. It contains
|
||||
no shell, package manager, BusyBox, or build tools. The native launcher removes
|
||||
the stale session lock and execs rTorrent; it also supplies the TCP health check.
|
||||
CI starts rTorrent and verifies an SCGI XML-RPC request before publication.
|
||||
|
||||
CI tests the assembled filesystem by starting rTorrent and making an SCGI XML-RPC
|
||||
request before publishing. The working `latest` tag is independent.
|
||||
|
||||
Your mounted `rtorrent.rc` must not depend on shell commands or utilities missing
|
||||
from this image (including `execute` hooks). Review those hooks before switching.
|
||||
Existing mount paths, SCGI port 5001, root UID and `HOME=/root` are preserved.
|
||||
Use the Compose overlay to replace the shell-based healthcheck:
|
||||
Use the default Compose file with the existing `.env` and mounted data:
|
||||
|
||||
```sh
|
||||
docker compose -f docker-compose.yml -f docker-compose.distroless.yml up -d
|
||||
docker compose pull
|
||||
docker compose up -d --force-recreate
|
||||
```
|
||||
|
||||
The overlay also selects the separate Flood distroless image. Keep the same `.env`
|
||||
values and mounted data. To roll back, use the base Compose file with `:latest`.
|
||||
For an existing custom Compose file, use `:latest` for both images and replace
|
||||
any shell-based rTorrent health check with:
|
||||
|
||||
```yaml
|
||||
healthcheck:
|
||||
test: ["CMD", "/usr/local/bin/rtorrent-entrypoint", "--healthcheck"]
|
||||
```
|
||||
|
||||
The separate `:distroless` tag and Compose overlay are retired. Both services in
|
||||
the default Compose file now use distroless `:latest`. Root UID, HOME=/root,
|
||||
SCGI port 5001, download paths and the session volume remain supported.
|
||||
Mounted `rtorrent.rc` execute hooks must use programs available in the image;
|
||||
shell commands and arbitrary external utilities are unavailable.
|
||||
Reference in new issue
Block a user