A lexicon-driven AppView for ATProto.
Something went wrong. Try again.
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667FROM node:22-alpine AS frontend
WORKDIR /app/webCOPY web/package.json web/package-lock.json ./RUN npm ciCOPY web/ .ENV NEXT_PUBLIC_BASE_PATH=/__HAPPYVIEW_BP__RUN npm run build
FROM rust:1.96.1-bookworm AS builder
WORKDIR /app
# Build dependencies first (cached until Cargo.toml/Cargo.lock change)# Every workspace member needs its manifest and a stub source here, or cargo# cannot resolve the workspace and the dependency-cache layer fails outright.# Adding a crate under crates/ means adding it to this list too.COPY Cargo.toml Cargo.lock ./COPY crates/happyview-nsid/Cargo.toml crates/happyview-nsid/COPY crates/happyview-plc/Cargo.toml crates/happyview-plc/COPY crates/happyview-scopes/Cargo.toml crates/happyview-scopes/RUN mkdir -p crates/happyview-nsid/src crates/happyview-plc/src crates/happyview-scopes/src \ && touch crates/happyview-nsid/src/lib.rs crates/happyview-plc/src/lib.rs crates/happyview-scopes/src/lib.rsRUN mkdir -p src/bin && echo "fn main() {}" > src/main.rs && touch src/lib.rs && echo "fn main() {}" > src/bin/migrate_lua_sql.rs && echo "fn main() {}" > src/bin/migrate_space_cids.rsENV SQLX_OFFLINE=trueRUN cargo build --release && rm -rf src target/release/.fingerprint/happyview-*
# Build application codeCOPY src/ src/COPY crates/ crates/COPY migrations/ migrations/ARG HAPPYVIEW_VERSIONENV HAPPYVIEW_VERSION=$HAPPYVIEW_VERSIONRUN cargo build --release
FROM scratch AS binaryCOPY --from=builder /app/target/release/happyview /target/release/happyview
FROM debian:bookworm-slim
RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates \ && rm -rf /var/lib/apt/lists/*
# NOTE: The container runs as root. A previous attempt to run as a non-root user# (uid 10001) broke upgrades for existing SQLite deployments — mounted data# volumes (e.g. Railway volumes, root-owned bind mounts) were not writable by the# non-root user, causing "attempt to write a readonly database" on the first# migration. Running as root sidesteps volume-ownership entirely. Non-root will be# reintroduced as a documented breaking change in a future major release, with the# entrypoint chowning the actual (operator-configurable) data directory before# dropping privileges. See the L5 note in the security review.WORKDIR /app
COPY --from=builder /app/target/release/happyview /usr/local/bin/happyviewRUN chmod +x /usr/local/bin/happyviewCOPY migrations/ /app/migrationsCOPY --from=frontend /app/web/out /srv/staticCOPY entrypoint.sh /entrypoint.shRUN chmod +x /entrypoint.sh && touch /srv/static/.base-path-pending
ENV STATIC_DIR=/srv/static
EXPOSE 3000
ENTRYPOINT ["/entrypoint.sh"]