From c0a851824112314d90ef6c130af75cb8a26efcd7 Mon Sep 17 00:00:00 2001 From: phoenix Date: Fri, 10 Jul 2026 17:35:03 -0400 Subject: [PATCH] bump: rust docker --- Dockerfile | 30 ++---------------------------- docker-compose.yml | 22 +++++++++------------- 2 files changed, 11 insertions(+), 41 deletions(-) diff --git a/Dockerfile b/Dockerfile index f9f29dd..1edb8d5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,14 +1,7 @@ -# Stage 1: Build the application -# Use a specific Rust version for reproducibility. Choose one that matches your development environment. -# Using slim variant for smaller base image -FROM rust:1.96.1 as builder +FROM rust:1.97 as builder -# Set the working directory inside the container WORKDIR /usr/src/app -# Install build dependencies if needed (e.g., for certain crates like sqlx with native TLS) -# RUN apt-get update && apt-get install -y pkg-config libssl-dev - # Install build dependencies if needed (e.g., git for cloning) RUN apt-get update && apt-get install -y --no-install-recommends \ pkg-config libssl3 \ @@ -16,55 +9,36 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ openssh-client git \ && rm -rf /var/lib/apt/lists/* -# << --- ADD HOST KEY HERE --- >> -# Replace 'yourgithost.com' with the actual hostname (e.g., github.com) RUN mkdir -p -m 0700 ~/.ssh && \ ssh-keyscan git.kundeng.us >> ~/.ssh/known_hosts -# Copy Cargo manifests COPY Cargo.toml Cargo.lock ./ -# Build *only* dependencies to leverage Docker cache -# This dummy build caches dependencies as a separate layer RUN --mount=type=ssh mkdir src && \ echo "fn main() {println!(\"if you see this, the build broke\")}" > src/main.rs && \ cargo build --release --quiet && \ - rm -rf src target/release/deps/textsender_auth* # Clean up dummy build artifacts + rm -rf src target/release/deps/textsender_auth* -# Copy the actual source code COPY src ./src -# If you have other directories like `templates` or `static`, copy them too COPY .env ./.env COPY migrations ./migrations -# << --- SSH MOUNT ADDED HERE --- >> -# Build *only* dependencies to leverage Docker cache -# This dummy build caches dependencies as a separate layer -# Mount the SSH agent socket for this command RUN --mount=type=ssh \ cargo build --release --quiet -# Stage 2: Create the final, smaller runtime image -# Use a minimal base image like debian-slim or even distroless for security/size FROM debian:trixie-slim # Install runtime dependencies if needed (e.g., SSL certificates) RUN apt-get update && apt-get install -y ca-certificates libssl-dev libssl3 && rm -rf /var/lib/apt/lists/* -# Set the working directory WORKDIR /usr/local/bin -# Copy the compiled binary from the builder stage COPY --from=builder /usr/src/app/target/release/textsender_auth . -# Copy other necessary files like .env (if used for runtime config) or static assets -# It's generally better to configure via environment variables in Docker though COPY --from=builder /usr/src/app/.env . COPY --from=builder /usr/src/app/migrations ./migrations -# Expose the port your Axum app listens on (e.g., 3000 or 8000) EXPOSE 9080 # Set the command to run your application -# Ensure this matches the binary name copied above CMD ["./textsender_auth"] diff --git a/docker-compose.yml b/docker-compose.yml index adc27c4..e9bd44e 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,28 +1,25 @@ version: '3.8' # Use a recent version services: - # Your Rust Application Service auth_api: - build: # Tells docker-compose to build the Dockerfile in the current directory + build: context: . - ssh: ["default"] # Uses host's SSH agent - container_name: textsender_auth # Optional: Give the container a specific name + ssh: ["default"] + container_name: textsender_auth ports: - # Map host port 8000 to container port 3000 (adjust as needed) - "9080:9080" env_file: - .env depends_on: auth_db: - condition: service_healthy # Wait for the DB to be healthy before starting the app - restart: unless-stopped # Optional: Restart policy + condition: service_healthy + restart: unless-stopped # PostgreSQL Database Service auth_db: - image: postgres:18.4-alpine # Use an official Postgres image (Alpine variant is smaller) - container_name: textsender_auth_db # Optional: Give the container a specific name + image: postgres:18.4-alpine + container_name: textsender_auth_db environment: - # These MUST match the user, password, and database name in the DATABASE_URL above POSTGRES_USER: ${DB_AUTH_USER:-textsender_op} POSTGRES_PASSWORD: ${DB_AUTH_PASSWORD:-password} POSTGRES_DB: ${DB_AUTH_NAME:-textsender_auth_db} @@ -38,9 +35,8 @@ services: timeout: 5s retries: 5 start_period: 10s - restart: always # Optional: Restart policy + restart: always -# Define the named volume for data persistence volumes: postgres_data: - driver: local # Use the default local driver + driver: local