From a19262d9a12a17eefed4b72a15b849a22446e6bd Mon Sep 17 00:00:00 2001 From: phoenix Date: Sun, 31 May 2026 18:00:23 -0400 Subject: [PATCH] Adding docker --- .dockerignore.yml | 17 +++++++++++ Dockerfile | 70 ++++++++++++++++++++++++++++++++++++++++++++++ docker-compose.yml | 45 +++++++++++++++++++++++++++++ 3 files changed, 132 insertions(+) create mode 100644 .dockerignore.yml create mode 100644 Dockerfile create mode 100644 docker-compose.yml diff --git a/.dockerignore.yml b/.dockerignore.yml new file mode 100644 index 0000000..4f436f8 --- /dev/null +++ b/.dockerignore.yml @@ -0,0 +1,17 @@ +# Ignore build artifacts +target/ +pkg/ + +# Ignore git directory +.git/ + +.gitea/ + +# Ignore environment files (configure via docker-compose instead) +.env* + +# Ignore OS specific files +*.DS_Store + +# Add any other files/directories you don't need in the image +# e.g., logs/, tmp/ diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..abad4dd --- /dev/null +++ b/Dockerfile @@ -0,0 +1,70 @@ +# Stage 1: Build the application +# Use a specific Rust version for reproducibility. Choose one that matches your development environment. +# Using slim variant for smaller base image +FROM rust:1.95 as builder + +# Set the working directory inside the container +WORKDIR /usr/src/app + +# Install build dependencies if needed (e.g., for certain crates like sqlx with native TLS) +# RUN apt-get update && apt-get install -y pkg-config libssl-dev + +# Install build dependencies if needed (e.g., git for cloning) +RUN apt-get update && apt-get install -y --no-install-recommends \ + pkg-config libssl3 \ + ca-certificates \ + openssh-client git \ + && rm -rf /var/lib/apt/lists/* + +# << --- ADD HOST KEY HERE --- >> +# Replace 'yourgithost.com' with the actual hostname (e.g., github.com) +RUN mkdir -p -m 0700 ~/.ssh && \ + ssh-keyscan git.kundeng.us >> ~/.ssh/known_hosts + +# Copy Cargo manifests +COPY Cargo.toml Cargo.lock ./ + +# Build *only* dependencies to leverage Docker cache +# This dummy build caches dependencies as a separate layer +RUN --mount=type=ssh mkdir src && \ + echo "fn main() {println!(\"if you see this, the build broke\")}" > src/main.rs && \ + cargo build --release --quiet && \ + rm -rf src target/release/deps/textsender_auth* # Clean up dummy build artifacts + +# Copy the actual source code +COPY src ./src +# If you have other directories like `templates` or `static`, copy them too +COPY .env ./.env +COPY migrations ./migrations + +# << --- SSH MOUNT ADDED HERE --- >> +# Build *only* dependencies to leverage Docker cache +# This dummy build caches dependencies as a separate layer +# Mount the SSH agent socket for this command +RUN --mount=type=ssh \ + cargo build --release --quiet + +# Stage 2: Create the final, smaller runtime image +# Use a minimal base image like debian-slim or even distroless for security/size +FROM debian:trixie-slim + +# Install runtime dependencies if needed (e.g., SSL certificates) +RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/* + +# Set the working directory +WORKDIR /usr/local/bin + +# Copy the compiled binary from the builder stage +COPY --from=builder /usr/src/app/target/release/textsender_auth . + +# Copy other necessary files like .env (if used for runtime config) or static assets +# It's generally better to configure via environment variables in Docker though +COPY --from=builder /usr/src/app/.env . +COPY --from=builder /usr/src/app/migrations ./migrations + +# Expose the port your Axum app listens on (e.g., 3000 or 8000) +EXPOSE 8001 + +# Set the command to run your application +# Ensure this matches the binary name copied above +CMD ["./textsender_auth"] diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..018a6cc --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,45 @@ +version: '3.8' # Use a recent version + +services: + # Your Rust Application Service + auth_api: + build: # Tells docker-compose to build the Dockerfile in the current directory + context: . + ssh: ["default"] # Uses host's SSH agent + container_name: textsender_auth # Optional: Give the container a specific name + ports: + # Map host port 8000 to container port 3000 (adjust as needed) + - "9080:9080" + env_file: + - .env + depends_on: + auth_db: + condition: service_healthy # Wait for the DB to be healthy before starting the app + restart: unless-stopped # Optional: Restart policy + + # PostgreSQL Database Service + auth_db: + image: postgres:18.4-alpine # Use an official Postgres image (Alpine variant is smaller) + container_name: textsender_auth_db # Optional: Give the container a specific name + environment: + # These MUST match the user, password, and database name in the DATABASE_URL above + POSTGRES_USER: ${POSTGRES_AUTH_USER:-textsender_op} + POSTGRES_PASSWORD: ${POSTGRES_AUTH_PASSWORD:-password} + POSTGRES_DB: ${POSTGRES_AUTH_DB:-textsender_auth_db} + volumes: + # Persist database data using a named volume + - postgres_data:/var/lib/postgresql + ports: [] + healthcheck: + # Checks if Postgres is ready to accept connections + test: ["CMD-SHELL", "pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB"] + interval: 10s + timeout: 5s + retries: 5 + start_period: 10s + restart: always # Optional: Restart policy + +# Define the named volume for data persistence +volumes: + postgres_data: + driver: local # Use the default local driver