Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
127 lines (111 loc) · 5.86 KB
/
Copy pathDockerfile
File metadata and controls
127 lines (111 loc) · 5.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
# FTW core container — Go host with SQLite, Lua drivers and web assets.
# The compiled Energyplan worker ships with Core; Core DP provides fallback.
#
# Multi-arch: linux/amd64 + linux/arm64 via docker buildx TARGETOS /
# TARGETARCH when available. Plain `docker build` falls back to the
# native Go arch inside the builder image.
# --- Builder ---------------------------------------------------------------
FROM --platform=$BUILDPLATFORM golang:1.27-bookworm AS builder
# Pure Go builds cross-compile without a native database toolchain.
ARG TARGETARCH
WORKDIR /src
# Cache the module download as its own layer so source edits don't
# bust the dep cache.
COPY go/go.mod go/go.sum ./go/
RUN cd go && go mod download
COPY go/ ./go/
COPY scripts/build-core.sh ./scripts/build-core.sh
ARG TARGETOS=linux
ARG VERSION=dev
ARG CANDIDATE_TAG
ARG BUILD_ALL=0
RUN FTW_BUILD_ALL="$BUILD_ALL" bash scripts/build-core.sh "$TARGETOS" "$TARGETARCH" /out
# Release archives and local cross builds use exactly the image's toolchain.
FROM scratch AS binaries
COPY --from=builder /out/ /
# --- Runtime ---------------------------------------------------------------
# Debian trixie-slim — current Debian stable (13), with one libc and one
# security stream to track.
#
# Pinned to the codename, not `stable-slim`: a suite alias would silently jump
# major versions on some future rebuild. The `debian base currency` workflow
# watches for a new stable and files an issue, so the bump stays deliberate.
#
# glibc also means the image can run ordinary prebuilt vendor binaries, which
# musl cannot, and ships a full userland for on-site debugging.
FROM debian:trixie-slim
# ca-certificates — HTTPS integrations.
# tzdata — timezone-aware price/plan windows. Without a zoneinfo tree
# time.Local silently degrades to UTC and mis-times plan
# boundaries with no error, so this is load-bearing.
# wget — the HEALTHCHECK below AND ftw-updater's readiness probe,
# which `docker exec`s wget in THIS image to decide whether
# an update commits. Debian slim does not include wget by
# default, so it must be installed explicitly; dropping it
# would make every self-update fail its health gate and roll
# back.
# libnss-mdns — resolves ".local" for glibc programs in the image (getent,
# wget), so in-container debugging agrees with the
# host. apt wires mdns4_minimal into /etc/nsswitch.conf on
# install. At run time it forwards to avahi-daemon over
# /run/avahi-daemon/socket, which must be bind-mounted; see
# docs/operations.md. It does nothing for the FTW binary
# itself: netgo/osusergo retain Go's name and user lookup.
RUN apt-get update && \
apt-get install -y --no-install-recommends \
ca-certificates tzdata wget libnss-mdns && \
rm -rf /var/lib/apt/lists/*
# Image layout:
# /app/ftw binary (immutable, replaced on upgrade)
# /app/drivers/ bundled Lua drivers (immutable, replaced on upgrade)
# /app/web/ bundled UI assets (immutable, replaced on upgrade)
# /app/data/ PERSISTENT — config.yaml, state.db, cold/, models
#
# The container's working directory is /app/data so that any *relative*
# path in the user's config (state.path: state.db, state.cold_dir: cold)
# resolves under the persistent volume by default. Without this, the
# binary would default-write state.db to its CWD and lose every byte
# on container recreate. See go/cmd/ftw/main.go:66 — there
# is no path resolution against the config file's directory; the open
# call is literally state.Open(cfg.State.Path).
COPY --from=builder --chown=100:101 /out/ftw /app/ftw
COPY --from=builder --chown=100:101 /out/ftw-backup /app/ftw-backup
COPY --chown=100:101 drivers/ /app/drivers/
COPY --chown=100:101 web/ /app/web/
COPY --chown=100:101 optimizer/native/bundle/ /app/optimizer/native/bundle/
COPY LICENSE NOTICE LICENSING.md THIRD-PARTY-NOTICES.txt /usr/share/doc/ftw/
RUN ln -s /app/ftw /app/forty-two-watts && \
mkdir -p /app/data /app/data/drivers /run/ftw-update && \
chown 100:101 /app/data /app/data/drivers /run/ftw-update
ENV HOME=/app/data
USER 100:101
WORKDIR /app/data
VOLUME ["/app/data"]
EXPOSE 8080
# Config + state both live in /app/data — one bind-mount is enough to
# persist everything across upgrades. Drivers and web are absolute
# paths into the immutable image layer so the bundled versions ship
# with each release.
#
# UID note: the process runs as uid 100 / gid 101 for compatibility with
# existing bind mounts. These are deliberately NUMERIC — no account is created
# and none is needed, which is why ENV HOME above is load-bearing. Verified on
# this base: uid 100 and gid 101 have no passwd/group entry, so ownership simply
# renders numerically. Do not renumber: gid 101 is what grants access to the
# updater socket, and existing installs (and every flashed SD card)
# already own their data dir as 100:101.
# Named docker volumes inherit ownership from the image
# automatically and just work. For HOST BIND MOUNTS, the host
# directory must be owned by uid 100 (or world-writable) before the
# container starts:
#
# mkdir -p /srv/ftw-data && chown -R 100:101 /srv/ftw-data
# docker run -v /srv/ftw-data:/app/data ghcr.io/srcfl/ftw:latest
#
# Without this the binary fails fast with "open state … unable to
# open database file" because SQLite can't create state.db inside
# a directory it doesn't own.
HEALTHCHECK --interval=10s --timeout=5s --start-period=20s --retries=12 \
CMD wget -q -T 4 -O /dev/null http://127.0.0.1:8080/api/health || exit 1
ENTRYPOINT ["/app/ftw"]
CMD ["-config", "/app/data/config.yaml", "-web", "/app/web", "-drivers", "/app/drivers", "-user-drivers", "/app/data/drivers"]