Files

27 lines
1.1 KiB
Docker
Raw Permalink Normal View History

# Portal, from the release tarball uhhm/portal publishes on
# project.uhhm.no (the same artifact the bare-metal instances run).
# PORTAL_RELEASE in .env pins the version; bumping it and rebuilding is
# the whole upgrade.
#
# Arch, because that is what the release is built on. The published
# binary is dynamically linked against that runner's glibc, so a
# debian:bookworm-slim base - glibc 2.36 against the 2.38 the binary
# asks for - starts and immediately exits with a version error. The
# base has to be at least as new as the builder, and the builder is
# Arch, so this is Arch. gdo's image is the same base for the same
# reason.
FROM archlinux:base
ARG PORTAL_RELEASE
RUN pacman -Sy --noconfirm --needed ca-certificates curl \
&& pacman -Scc --noconfirm \
&& rm -rf /var/cache/pacman/pkg/* /var/lib/pacman/sync/*
WORKDIR /app
RUN curl -sfL "https://project.uhhm.no/uhhm/portal/releases/download/${PORTAL_RELEASE}/portal-${PORTAL_RELEASE}.tar.gz" \
| tar -xz -C /app \
&& test -x /app/portal
# A non-root user; the image ships nothing writable it needs.
RUN useradd --system --no-create-home portal
USER portal
EXPOSE 3000
CMD ["/app/portal"]