g1t/deploy/self-host/Dockerfile
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Running g1t yourself: the design, a docker compose proof, and a guide to what works today | 1 | # Self-hosted g1t: every Worker of the core forge in one workerd, through |
| 2 | # `wrangler dev`, with D1, KV and Queues kept on the /data volume. | |
| 3 | # Build context: the repository root (see docker-compose.yml). | |
| 4 | ||
| 5 | # ── The Rust services, compiled to WebAssembly as they are for Workers ── | |
| 6 | FROM rust:1-slim-bookworm AS rust | |
| 7 | RUN apt-get update \ | |
| 8 | && apt-get install -y --no-install-recommends curl ca-certificates pkg-config libssl-dev \ | |
| 9 | && rm -rf /var/lib/apt/lists/* \ | |
| 10 | && rustup target add wasm32-unknown-unknown \ | |
| 11 | && cargo install -q worker-build@0.8.7 --locked | |
| 12 | WORKDIR /src | |
| 13 | COPY Cargo.toml Cargo.lock ./ | |
| 14 | COPY apps/api apps/api | |
| 15 | COPY crates crates | |
| 16 | COPY services services | |
| 17 | # The same build hosted g1t deploys (each wrangler.jsonc's build command). | |
| 18 | # No cache mount for target/: cargo trusts file times, and a cached build | |
| 19 | # from a newer tree would be taken as fresh for an older one. | |
| 20 | RUN --mount=type=cache,target=/usr/local/cargo/registry \ | |
| 21 | for service in identity repos work events search billing security actions webhooks integrations; do \ | |
| 22 | (cd services/$service && worker-build --release) || exit 1; \ | |
| 23 | done | |
| 24 | ||
| 25 | # ── The site, built by React Router; the TypeScript services' packages ── | |
| 26 | FROM node:24-bookworm-slim AS node | |
| 27 | WORKDIR /app | |
| 28 | COPY . . | |
| 29 | RUN npm ci --no-audit --no-fund \ | |
| 30 | --include-workspace-root \ | |
| status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas | 31 | -w @g1t/web -w @g1t/projects -w @g1t/deployments -w @g1t/contracts -w @g1t/theme -w @g1t/status \ |
| Running g1t yourself: the design, a docker compose proof, and a guide to what works today | 32 | && npm run build -w @g1t/web |
| 33 | ||
| 34 | # ── Runtime ── | |
| 35 | FROM node:24-bookworm-slim | |
| 36 | RUN apt-get update \ | |
| 37 | && apt-get install -y --no-install-recommends ca-certificates \ | |
| 38 | && rm -rf /var/lib/apt/lists/* | |
| 39 | WORKDIR /app | |
| 40 | COPY --from=node --chown=node:node /app /app | |
| 41 | COPY --from=rust /src/services /tmp/rust-services | |
| 42 | RUN for service in identity repos work events search billing security actions webhooks integrations; do \ | |
| 43 | cp -r /tmp/rust-services/$service/build services/$service/build; \ | |
| 44 | done \ | |
| 45 | && rm -rf /tmp/rust-services \ | |
| 46 | && mkdir -p /data && chown node:node /data | |
| 47 | ENV WRANGLER_SEND_METRICS=false \ | |
| 48 | PUBLIC_URL=http://localhost:8787 \ | |
| 49 | GITSTORE_URL=http://gitstore:8080 \ | |
| 50 | G1T_DATA=/data | |
| 51 | VOLUME /data | |
| 52 | EXPOSE 8787 | |
| 53 | USER node | |
| 54 | CMD ["bash", "deploy/self-host/start.sh"] |