# syntax=docker/dockerfile:1 # Build the tranquil-pds fork straight from its git branch. # debian-slim final stage (not distroless) so `wget` works for the healthcheck. FROM scratch AS tranquil ADD https://tangled.org/oppi.li/tranquil-pds.git#op/vynuyrksymxl / FROM node:24-trixie-slim AS frontend RUN corepack enable && corepack prepare pnpm@latest --activate COPY --from=tranquil frontend /app/frontend WORKDIR /app/frontend RUN pnpm install --frozen-lockfile RUN pnpm build FROM rust:1.96-slim-trixie AS builder RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates pkg-config libssl-dev mold clang protobuf-compiler \ && rm -rf /var/lib/apt/lists/* ENV RUSTFLAGS="-C linker=clang -C link-arg=-fuse-ld=mold" COPY --from=tranquil Cargo.toml Cargo.lock /app/ COPY --from=tranquil .sqlx /app/.sqlx COPY --from=tranquil crates /app/crates COPY --from=tranquil migrations /app/migrations WORKDIR /app # Trust the mounted Compose CA while retaining certificate verification. # Tranquil's similarly named native-tls-roots feature disables verification # for metadata fetches; enable reqwest's actual native root support instead. RUN --mount=type=cache,target=/usr/local/cargo/registry \ --mount=type=cache,target=/usr/local/cargo/git \ --mount=type=cache,target=/app/target \ SQLX_OFFLINE=true cargo build --locked -p tranquil-server --features reqwest/rustls-tls-native-roots && cp /app/target/debug/tranquil-server /tranquil-server FROM debian:trixie-slim RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates wget \ && rm -rf /var/lib/apt/lists/* COPY --from=builder /tranquil-server /usr/local/bin/tranquil-pds COPY --from=frontend /app/frontend/dist /var/lib/tranquil-pds/frontend RUN mkdir -p /var/lib/tranquil-pds/blobs /var/lib/tranquil-pds/store WORKDIR /var/lib/tranquil-pds ENV SERVER_HOST=[::] ENV SERVER_PORT=3000 EXPOSE 3000 ENTRYPOINT ["/usr/local/bin/tranquil-pds"]