From a8fceb937a4eb467ed891bc7e95e7a564443e72c Mon Sep 17 00:00:00 2001 From: Andrei Jiroh Halili Date: Sat, 4 Jul 2026 17:49:00 +0800 Subject: [PATCH] build(docker): tweak deploy stage for normal usage We might tweak the Docker image name to use the recaptime-dev/infra/docker GitLab namespace later once the build goes green. Signed-off-by: Andrei Jiroh Halili --- build/Dockerfile | 30 ++++++++++++++++++++---------- docs/invite-codes.md | 2 +- 2 files changed, 21 insertions(+), 11 deletions(-) diff --git a/build/Dockerfile b/build/Dockerfile index 855e0ef..0dd6377 100644 --- a/build/Dockerfile +++ b/build/Dockerfile @@ -1,3 +1,4 @@ +#syntax=docker/dockerfile:experimental FROM alpine:edge AS starting-point ARG TRANQUIL_PDS_REPO=https://tangled.org/tranquil.farm/tranquil-pds @@ -14,7 +15,7 @@ FROM node:26-alpine AS frontend RUN npm install -g pnpm@latest WORKDIR /app -COPY --from=starting-point /src/frontend/ ./ +COPY --from=starting-point /src/ ./ RUN pnpm install --frozen-lockfile && pnpm build # TODO: Switch to Alpine Linux-based builder image @@ -43,11 +44,8 @@ RUN mkdir -p /stage/var/lib/tranquil-pds/blobs /stage/var/lib/tranquil-pds/store ENV RUSTFLAGS="-C linker=clang -C link-arg=-fuse-ld=mold" WORKDIR /app ARG SLIM="false" -COPY --from=starting-point /src/Cargo.toml /src/Cargo.lock /src/.sqlx /src/crates /src/migrations ./ -RUN --mount=type=cache,id=cargo-registry,target=/usr/local/cargo/registry \ - --mount=type=cache,id=cargo-git,target=/usr/local/cargo/git \ - --mount=type=cache,id=tranquil-target,target=/app/target,sharing=locked \ - if [ "$SLIM" = "true" ]; then \ +COPY --from=starting-point /src/ ./ +RUN if [ "$SLIM" = "true" ]; then \ SQLX_OFFLINE=true cargo build --release -p tranquil-server --no-default-features; \ else \ SQLX_OFFLINE=true cargo build --release -p tranquil-server; \ @@ -56,10 +54,22 @@ RUN --mount=type=cache,id=cargo-registry,target=/usr/local/cargo/registry \ if [ "$COMPRESS" = "true" ] && command -v upx >/dev/null 2>&1; then upx --best --lzma /tmp/tranquil-pds; fi FROM alpine:edge AS deploy -WORKDIR /app/dist + +WORKDIR /app + COPY --from=builder /tmp/tranquil-pds /app/dist/tranquil-pds -#COPY --from=builder --chown=65532:65532 /stage/var/lib/tranquil-pds /app/dist/ COPY --from=frontend --chown=65532:65532 /app/dist /app/dist/frontend -ENTRYPOINT [ "/bin/sh", "-c" ] -CMD [ "cp", "-rv", "/app/dist/*", "/out" ] +RUN mkdir -p /app/data/blobs && mkdir /app/data/store \ + && apk add --no-cache dumb-init + +ENV FRONTEND_DIR=/app/dist/frontend \ + TRANQUIL_STORE_DATA_DIR=/app/data/store \ + BLOB_STORAGE_PATH=/app/data/blobs \ + SERVER_HOST=[::] SERVER_PORT=3000 + +EXPOSE 3000 +VOLUME [ "/app/data" ] + +ENTRYPOINT [ "dumb-init" ] +CMD [ "/app/dist/tranquil-pds" ] diff --git a/docs/invite-codes.md b/docs/invite-codes.md index 3f01963..b240007 100644 --- a/docs/invite-codes.md +++ b/docs/invite-codes.md @@ -1,6 +1,6 @@ # Invite Codes for Account Creation and Migration -Invite codes are enabled in our PDS through the `INVITE_CODE_REQUIRED` environment variable in our production configuration to prevent abuse caused by automated account creation (Tranquil PDS does not have CAPTCHA-based flow for ratelimiting these and requires email verification) while allowing us to balance user growth of our instance and the costs of running one (i.e. Cloudflare R2 storage, Uberspace hosting account, etc). +Invite codes are enabled in our PDS through the `INVITE_CODE_REQUIRED` environment variable in our production configuration to prevent abuse caused by automated account creation (Tranquil PDS does not have CAPTCHA-based flow for ratelimiting these and involves email verification instead) while allowing us to balance user growth of our instance and the costs of running one (i.e. Cloudflare R2 storage, Uberspace hosting account, etc). ## Requesting an Invite Code -- 2.51.2