-
Notifications
You must be signed in to change notification settings - Fork 99
Expand file tree
/
Copy pathDockerfile
More file actions
137 lines (111 loc) · 4.19 KB
/
Copy pathDockerfile
File metadata and controls
137 lines (111 loc) · 4.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
# syntax=docker/dockerfile:1
# check=error=true;skip=SecretsUsedInArgOrEnv
# This Dockerfile is designed for production, not development. Use with Kamal or build'n'run by hand:
# docker build -t battlemage .
# docker run -d -p 80:80 -e RAILS_MASTER_KEY=<value from config/master.key> --name battlemage battlemage
# For a containerized dev environment, see Dev Containers: https://guides.rubyonrails.org/getting_started_with_devcontainer.html
# Make sure RUBY_VERSION matches the Ruby version in .ruby-version
ARG RUBY_VERSION=3.4.3
ARG LIBHEIF_VERSION=1.23.2
ARG LIBHEIF_SHA256=8bd5d41d19dc84536d118b04774709f244df6104ef66d623dad5fa4650143405
FROM docker.io/library/ruby:$RUBY_VERSION-slim AS libheif-build
ARG LIBHEIF_VERSION
ARG LIBHEIF_SHA256
RUN apt-get update -qq && \
apt-get install --no-install-recommends -y \
build-essential cmake pkg-config \
libde265-dev libaom-dev libdav1d-dev libx265-dev zlib1g-dev \
curl ca-certificates && \
rm -rf /var/lib/apt/lists/*
RUN curl -fsSL https://github.com/strukturag/libheif/releases/download/v${LIBHEIF_VERSION}/libheif-${LIBHEIF_VERSION}.tar.gz \
-o libheif.tar.gz && \
echo "${LIBHEIF_SHA256} libheif.tar.gz" | sha256sum -c && \
tar xzf libheif.tar.gz && \
cd libheif-${LIBHEIF_VERSION} && \
cmake --preset=release -DWITH_EXAMPLES=OFF -DENABLE_PLUGIN_LOADING=NO && \
make -j$(nproc) && \
make install && \
ldconfig
FROM docker.io/library/ruby:$RUBY_VERSION-slim AS base
# Rails app lives here
WORKDIR /rails
# Install base packages
RUN apt-get update -qq && \
apt-get install --no-install-recommends -y \
curl \
wget \
procps \
lsof \
strace \
less \
libjemalloc2 \
libvips \
imagemagick \
file \
git \
libopenblas0 \
liblapack3 \
ffmpeg \
nodejs && \
rm -rf /var/lib/apt/lists/* /var/cache/apt/archives/*
COPY --from=libheif-build /usr/local/lib/libheif* /usr/local/lib/
RUN ldconfig
# Set production environment
ENV RAILS_ENV="production" \
BUNDLE_DEPLOYMENT="1" \
BUNDLE_PATH="/usr/local/bundle" \
BUNDLE_WITHOUT="development"
# Throw-away build stage to reduce size of final image
FROM base AS build
# Install packages needed to build gems
RUN apt-get update -qq && \
apt-get install --no-install-recommends -y \
build-essential \
git \
libyaml-dev \
pkg-config \
libffi-dev \
libopenblas-dev \
liblapack-dev && \
rm -rf /var/lib/apt/lists /var/cache/apt/archives
# Install Node.js and enable Corepack for Yarn Berry
RUN apt-get update -qq && \
apt-get install --no-install-recommends -y nodejs npm && \
npm install -g corepack && \
corepack enable && \
rm -rf /var/lib/apt/lists /var/cache/apt/archives
# Install application gems
COPY Gemfile Gemfile.lock ./
COPY engines/raffle/raffle.gemspec ./engines/raffle/
COPY bin/install-sqlite-vec-arm64 ./bin/
RUN ./bin/install-sqlite-vec-arm64 && \
bundle install && \
rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git && \
bundle exec bootsnap precompile --gemfile
# Install JavaScript dependencies for jsbundling-rails
COPY package.json yarn.lock .yarnrc.yml ./
RUN yarn install --immutable
# Copy application code
COPY . .
# Precompile bootsnap code for faster boot times
RUN bundle exec bootsnap precompile app/ lib/
# Precompiling assets for production without requiring secret RAILS_MASTER_KEY
RUN SECRET_KEY_BASE_DUMMY=1 ./bin/rails assets:precompile
# Final stage for app image
FROM base
# for dearest max-- this adds the git SHA because its missing during ghcr builds!
ARG GIT_COMMIT_SHA
ENV GIT_COMMIT_SHA=${GIT_COMMIT_SHA}
# Copy built artifacts: gems, application
COPY --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}"
COPY --from=build /rails /rails
# Run and own only the runtime files as a non-root user for security
RUN groupadd --system --gid 1000 rails && \
useradd rails --uid 1000 --gid 1000 --create-home --shell /bin/bash && \
chown -R rails:rails db log storage tmp public
USER 1000:1000
# Entrypoint prepares the database.
ENTRYPOINT ["/rails/bin/docker-entrypoint"]
# Start server via Thruster by default, this can be overwritten at runtime
EXPOSE 80
CMD ["./bin/thrust", "./bin/rails", "server"]