# Not for production: the migrator serves its did:web over plain http and trusts caddy's ca. FROM golang:1.26-alpine AS builder RUN apk add --no-cache git build-base sqlite-dev ENV CGO_ENABLED=1 ENV GOCACHE=/go/cache ENV GOMODCACHE=/go/mod WORKDIR /src COPY go.mod go.sum ./ RUN --mount=type=cache,target=/go/cache \ --mount=type=cache,target=/go/mod \ go mod download COPY . . RUN --mount=type=cache,target=/go/cache \ --mount=type=cache,target=/go/mod \ go build -tags libsqlite3 -o /out/migrator ./cmd/migrator FROM alpine:3.24 # git-lfs is not optional: the worker pushes lfs objects before refs, and a # mirror that lands without its objects is the failure this service avoids RUN apk add --no-cache ca-certificates git git-lfs sqlite-libs tini COPY --from=builder /out/migrator /usr/local/bin/migrator VOLUME /var/lib/migrator EXPOSE 6767 ENTRYPOINT ["/sbin/tini", "--"] CMD ["sh", "-c", "if [ -f /usr/local/share/ca-certificates/caddy.crt ]; then update-ca-certificates; fi && exec /usr/local/bin/migrator serve"]