g1t/deploy/self-host/Dockerfile

56 lines2,359 bytesCodeBlame
1# Self-hosted g1t: every Worker of the core forge in one workerd, through
2# `wrangler dev`, with D1, KV and Queues kept on the /data volume.
3# Build context: the repository root (see docker-compose.yml).
4
5# ── The Rust services, compiled to WebAssembly as they are for Workers ──
6FROM rust:1-slim-bookworm AS rust
7RUN apt-get update \
8 && apt-get install -y --no-install-recommends curl ca-certificates pkg-config libssl-dev \
9 && rm -rf /var/lib/apt/lists/* \
10 && rustup target add wasm32-unknown-unknown \
11 && cargo install -q worker-build@0.8.7 --locked
12WORKDIR /src
13COPY Cargo.toml Cargo.lock ./
14COPY apps/api apps/api
15COPY crates crates
16COPY services services
17# The same build hosted g1t deploys (each wrangler.jsonc's build command).
18# No cache mount for target/: cargo trusts file times, and a cached build
19# from a newer tree would be taken as fresh for an older one.
20RUN --mount=type=cache,target=/usr/local/cargo/registry \
21 for service in identity repos work events search billing security actions webhooks integrations packages; do \
22 (cd services/$service && worker-build --release) || exit 1; \
23 done \
24 && (cd apps/api && worker-build --release)
25
26# ── The site, built by React Router; the TypeScript services' packages ──
27FROM node:24-bookworm-slim AS node
28WORKDIR /app
29COPY . .
30RUN npm ci --no-audit --no-fund \
31 --include-workspace-root \
32 -w @g1t/web -w @g1t/projects -w @g1t/deployments -w @g1t/contracts -w @g1t/theme -w @g1t/status \
33 && npm run build -w @g1t/web
34
35# ── Runtime ──
36FROM node:24-bookworm-slim
37RUN apt-get update \
38 && apt-get install -y --no-install-recommends ca-certificates \
39 && rm -rf /var/lib/apt/lists/*
40WORKDIR /app
41COPY --from=node --chown=node:node /app /app
42COPY --from=rust /src/services /tmp/rust-services
43COPY --from=rust --chown=node:node /src/apps/api/build apps/api/build
44RUN for service in identity repos work events search billing security actions webhooks integrations packages; do \
45 cp -r /tmp/rust-services/$service/build services/$service/build; \
46 done \
47 && rm -rf /tmp/rust-services \
48 && mkdir -p /data && chown node:node /data
49ENV WRANGLER_SEND_METRICS=false \
50 PUBLIC_URL=http://localhost:8787 \
51 GITSTORE_URL=http://gitstore:8080 \
52 G1T_DATA=/data
53VOLUME /data
54EXPOSE 8787 8789
55USER node
56CMD ["bash", "deploy/self-host/start.sh"]