# Portal, from the release tarball uhhm/portal publishes on # project.uhhm.no (the same artifact the bare-metal instances run). # PORTAL_RELEASE in .env pins the version; bumping it and rebuilding is # the whole upgrade. # # Arch, because that is what the release is built on. The published # binary is dynamically linked against that runner's glibc, so a # debian:bookworm-slim base - glibc 2.36 against the 2.38 the binary # asks for - starts and immediately exits with a version error. The # base has to be at least as new as the builder, and the builder is # Arch, so this is Arch. gdo's image is the same base for the same # reason. FROM archlinux:base ARG PORTAL_RELEASE RUN pacman -Sy --noconfirm --needed ca-certificates curl \ && pacman -Scc --noconfirm \ && rm -rf /var/cache/pacman/pkg/* /var/lib/pacman/sync/* WORKDIR /app RUN curl -sfL "https://project.uhhm.no/uhhm/portal/releases/download/${PORTAL_RELEASE}/portal-${PORTAL_RELEASE}.tar.gz" \ | tar -xz -C /app \ && test -x /app/portal # A non-root user; the image ships nothing writable it needs. RUN useradd --system --no-create-home portal USER portal EXPOSE 3000 CMD ["/app/portal"]