27 lines
1.1 KiB
Docker
27 lines
1.1 KiB
Docker
# Portal, from the release tarball uhhm/portal publishes on
|
|
# project.uhhm.no (the same artifact the bare-metal instances run).
|
|
# PORTAL_RELEASE in .env pins the version; bumping it and rebuilding is
|
|
# the whole upgrade.
|
|
#
|
|
# Arch, because that is what the release is built on. The published
|
|
# binary is dynamically linked against that runner's glibc, so a
|
|
# debian:bookworm-slim base - glibc 2.36 against the 2.38 the binary
|
|
# asks for - starts and immediately exits with a version error. The
|
|
# base has to be at least as new as the builder, and the builder is
|
|
# Arch, so this is Arch. gdo's image is the same base for the same
|
|
# reason.
|
|
FROM archlinux:base
|
|
ARG PORTAL_RELEASE
|
|
RUN pacman -Sy --noconfirm --needed ca-certificates curl \
|
|
&& pacman -Scc --noconfirm \
|
|
&& rm -rf /var/cache/pacman/pkg/* /var/lib/pacman/sync/*
|
|
WORKDIR /app
|
|
RUN curl -sfL "https://project.uhhm.no/uhhm/portal/releases/download/${PORTAL_RELEASE}/portal-${PORTAL_RELEASE}.tar.gz" \
|
|
| tar -xz -C /app \
|
|
&& test -x /app/portal
|
|
# A non-root user; the image ships nothing writable it needs.
|
|
RUN useradd --system --no-create-home portal
|
|
USER portal
|
|
EXPOSE 3000
|
|
CMD ["/app/portal"]
|