Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
202 lines (179 loc) · 9.9 KB
/
Copy pathDockerfile
File metadata and controls
202 lines (179 loc) · 9.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
# Debian 13 (Trixie) slim - amd64
# Version: trixie-slim (pinned digest = 13.6-slim / trixie-20260824-slim, glibc 2.41)
# NOTE: the previous digest (b6e2a152...) actually resolved to Debian 12
# (bookworm, glibc 2.36), which is too old for the CI-built binaries
# (they require GLIBC_2.38 / GLIBCXX_3.4.32) -> CrashLoopBackOff.
# NOTE: keep the "trixie-slim" tag in the reference. A bare "debian@sha256:..."
# has no tag for Dependabot to track, so it gets bumped against the full
# (non-slim) image (see reverted bump 0f10566: 1d3c811 -> 34cd9e9).
FROM --platform=$BUILDPLATFORM debian:trixie-slim@sha256:d7e12182ce18b85b93007c1dedf31f2d29e01ccf3182cc4017c709b6259bc132 AS build
ARG OWNER=nam20485
ARG VCPKG_BINARY_SOURCES=""
# USE_VCPKG_CACHE=1 enables read-only consumption of the GitHub Packages vcpkg
# binary cache (local dev / consumer builds). USE_VCPKG_CACHE=0 keeps the legacy
# write-enabled behavior (CI uploads via the in-image NuGet source).
#
# Tokens are supplied as BuildKit secrets (see the RUN --mount=type=secret below),
# NOT as ARGs, so they are not passed as build args, not printed in build logs,
# and kept out of the final image. (They do exist in the *build* stage's layer
# contents — e.g. the generated NuGet config — so avoid exporting build-stage
# layers to a shared cache; the published `run` stage contains no token.)
# id=github_token GitHub PAT (write:packages) — used by the USE_VCPKG_CACHE=0 path
# id=nuget_auth_token GitHub PAT (read:packages) — used by the USE_VCPKG_CACHE=1 path
ARG USE_VCPKG_CACHE=0
# install dependencies
RUN apt-get update && \
apt-get install -y -q --no-install-recommends \
curl \
apt-transport-https \
ca-certificates \
cmake \
g++ \
ninja-build \
build-essential \
git \
zip \
unzip \
tar \
pkg-config \
mono-complete \
linux-libc-dev \
python3 \
&& \
apt-get clean && \
rm -rf /var/lib/apt/lists/*
# install vcpkg
ENV VCPKG_ROOT=/root/src/github/microsoft/vcpkg
RUN git clone https://github.com/Microsoft/vcpkg.git ${VCPKG_ROOT}
WORKDIR ${VCPKG_ROOT}
RUN ./bootstrap-vcpkg.sh
# set vcpkg to use NuGet for binary caching
ENV VCPKG_BINARY_SOURCES=${VCPKG_BINARY_SOURCES}
# When USE_VCPKG_CACHE=1 (local dev): generate a read-only nuget config so vcpkg
# downloads pre-built packages from GitHub Packages without uploading.
# When USE_VCPKG_CACHE=0 (CI / default): set up the in-image write-enabled NuGet
# source so vcpkg uploads built binaries to GitHub Packages.
RUN --mount=type=secret,id=github_token \
--mount=type=secret,id=nuget_auth_token \
if [ "${USE_VCPKG_CACHE}" = "1" ]; then \
if [ ! -s /run/secrets/nuget_auth_token ]; then \
echo "ERROR: USE_VCPKG_CACHE=1 requires the 'nuget_auth_token' build secret, but it is missing/empty." >&2; \
echo " Provide NUGET_AUTH_TOKEN (GitHub PAT with read:packages scope) in the build environment." >&2; \
exit 1; \
fi; \
mkdir -p /etc/vcpkg && \
printf '<?xml version="1.0" encoding="utf-8"?>\n<configuration>\n <packageSources>\n <clear />\n <add key="GitHubPackages-OdbDesign" value="https://nuget.pkg.github.com/%s/index.json" />\n </packageSources>\n <packageSourceCredentials>\n <GitHubPackages-OdbDesign>\n <add key="Username" value="%s" />\n <add key="ClearTextPassword" value="%s" />\n </GitHubPackages-OdbDesign>\n </packageSourceCredentials>\n</configuration>\n' "${OWNER}" "${OWNER}" "$(cat /run/secrets/nuget_auth_token)" \
> /etc/vcpkg/local.nuget.config; \
else \
if [ ! -s /run/secrets/github_token ]; then \
echo "ERROR: USE_VCPKG_CACHE=0 requires the 'github_token' build secret, but it is missing/empty." >&2; \
echo " Provide GITHUB_TOKEN (GitHub PAT with write:packages scope) in the build environment." >&2; \
exit 1; \
fi; \
mono `./vcpkg fetch nuget | tail -n 1` \
sources add \
-source "https://nuget.pkg.github.com/${OWNER}/index.json" \
-storepasswordincleartext \
-name "GitHub" \
-username ${OWNER} \
-password "$(cat /run/secrets/github_token)" && \
mono `./vcpkg fetch nuget | tail -n 1` \
setapikey "$(cat /run/secrets/github_token)" \
-source "https://nuget.pkg.github.com/${OWNER}/index.json"; \
fi
# pre-install vcpgk packages BEFORE cmake configure
# match the linux-dynamic-release preset's triplet so the pre-install is what
# the configure step actually consumes (manifest mode would install it anyway)
RUN mkdir -p /src/OdbDesign
WORKDIR /src/OdbDesign
COPY ./vcpkg.json .
COPY ./vcpkg-configuration.json .
RUN ${VCPKG_ROOT}/vcpkg install --triplet x64-linux-dynamic
# RUN --mount=type=cache,target=/root/.cache \
# ${VCPKG_ROOT}/vcpkg install
# copy source
COPY . .
# configure & build using presets
# linux-dynamic-release (shared protobuf/gRPC runtime — the static linux-release
# preset loads two protobuf copies and crashes; see docs/completed/linux-dynamic-release-plan.md)
RUN cmake --preset linux-dynamic-release
RUN cmake --build --preset linux-dynamic-release
# # linux-debug
# RUN cmake --preset linux-debug
# RUN cmake --build --preset linux-debug
# much smaller runtime image
# Debian 13 (Trixie) slim - amd64
# Version: trixie-slim (pinned digest = 13.6-slim / trixie-20260824-slim, glibc 2.41)
# NOTE: keep in sync with the build stage digest (see note above).
FROM debian:trixie-slim@sha256:d7e12182ce18b85b93007c1dedf31f2d29e01ccf3182cc4017c709b6259bc132 AS run
# ARG ODBDESIGN_SERVER_REQUEST_USERNAME=""
# ARG ODBDESIGN_SERVER_REQUEST_PASSWORD=""
LABEL org.opencontainers.image.source=https://github.com/nam20485/OdbDesign \
org.opencontainers.image.authors=https://github.com/nam20485 \
org.opencontainers.image.description="A free open source cross-platform C++ library for parsing ODB++ Design archives and accessing their data. Exposed via a REST API (port 8888) and a gRPC API (port 50051) packaged inside of a Docker image. The OdbDesign Docker image runs the OdbDesignServer executable, which starts both servers in the same process and shares a single DesignCache." \
org.opencontainers.image.licenses=AGPL-3.0-only \
org.opencontainers.image.url=https://nam20485.github.io/OdbDesign \
org.opencontainers.image.documentation=https://github.com/nam20485/OdbDesign?tab=readme-ov-file \
org.opencontainers.image.title="OdbDesign Server"
EXPOSE 8888 50051
# install dependencies (curl for healthcheck, 7z for archive extraction)
RUN apt-get update && \
apt-get install -y -q --no-install-recommends \
curl \
apt-transport-https \
ca-certificates \
p7zip-full \
&& \
apt-get clean && \
rm -rf /var/lib/apt/lists/*
# # --- gRPC health check (easy to disable: comment out the two blocks below) ---
# # Download grpc_health_probe binary
# ARG GRPC_HEALTH_PROBE_VERSION=v0.4.24
# RUN curl -sL -o /bin/grpc_health_probe \
# https://github.com/grpc-ecosystem/grpc-health-probe/releases/download/${GRPC_HEALTH_PROBE_VERSION}/grpc_health_probe-linux-amd64 && \
# chmod +x /bin/grpc_health_probe
# # gRPC-specific healthcheck (comment out to disable, re-enable HTTP-only HEALTHCHECK above)
# HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
# CMD /bin/grpc_health_probe -addr=localhost:50051 || exit 1
# test 7z install
RUN 7z -h
# create non-root user
RUN groupadd --gid 10001 odbdesign && \
useradd --uid 10001 --gid odbdesign --create-home --shell /usr/sbin/nologin odbdesign
RUN mkdir --parents /OdbDesign/bin /OdbDesign/templates /OdbDesign/designs
WORKDIR /OdbDesign
# copy binaries
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/OdbDesignLib/*.so ./bin/
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/Utils/*.so ./bin/
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/OdbDesignServer/OdbDesignServer ./bin/
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/OdbDesignServer/*.so ./bin/
# vcpkg shared libraries (protobuf, gRPC, libarchive, ...) required by the
# linux-dynamic-release build; discovered via LD_LIBRARY_PATH=/OdbDesign/bin
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/vcpkg_installed/x64-linux-dynamic/lib/*.so* ./bin/
# OpenSSL 3 provider modules (resolved relative to libcrypto.so's directory)
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/vcpkg_installed/x64-linux-dynamic/lib/ossl-modules ./bin/ossl-modules
# gRPC service config (loaded by RunGrpcServer from exeDir/config.json)
COPY --from=build /src/OdbDesign/OdbDesignServer/config.json ./bin/config.json
COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/OdbDesignTests/OdbDesignTests ./bin/
# COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/OdbDesignApp/OdbDesignApp ./bin/
# COPY --from=build /src/OdbDesign/out/build/linux-dynamic-release/OdbDesignApp/*.so ./bin/
# copy templates directory
COPY --from=build /src/OdbDesign/OdbDesignServer/templates/* ./templates
# set ownership to non-root user
RUN chmod +x ./bin/OdbDesignServer && \
chown --recursive odbdesign:odbdesign /OdbDesign
USER odbdesign
# Docker health check using existing HTTP endpoint. Runs inside the container
# as the image's configured user (odbdesign, the final USER above) — HEALTHCHECK
# placement does not affect that; kept after USER purely for readability of the
# non-root runtime stage.
HEALTHCHECK --interval=30s --timeout=3s --start-period=10s --retries=3 \
CMD curl -f http://localhost:8888/healthz/live || exit 1
# create designs directory
# required to be volume mounted!
#RUN mkdir ./designs
# run
ENV LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/OdbDesign/bin
# ENV ODBDESIGN_SERVER_REQUEST_USERNAME=${ODBDESIGN_SERVER_REQUEST_USERNAME}
# ENV ODBDESIGN_SERVER_REQUEST_PASSWORD=${ODBDESIGN_SERVER_REQUEST_PASSWORD}
ENTRYPOINT [ "./bin/OdbDesignServer", "--designs-dir", "./designs", "--templates-dir", "./templates" ]