Repository navigation
Expand file tree
/
Copy pathDockerfile.prebuilt
More file actions
87 lines (72 loc) · 4.21 KB
/
Copy pathDockerfile.prebuilt
File metadata and controls
87 lines (72 loc) · 4.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
# Dockerfile.prebuilt - Lightweight runtime-only image using pre-built artifacts
# This Dockerfile is used by the Docker Publish workflow to create images from
# artifacts built by the CMake Multi-Platform workflow, avoiding a full rebuild.
# Debian 13 (Trixie) slim - amd64
# Version: trixie-slim (pinned digest = 13.6-slim / trixie-20260824-slim, glibc 2.41)
# NOTE: the previous digest (b6e2a152...) actually resolved to Debian 12
# (bookworm, glibc 2.36), which is too old for the CI-built artifacts
# (they require GLIBC_2.38 / GLIBCXX_3.4.32) -> CrashLoopBackOff.
# NOTE: keep the "trixie-slim" tag in the reference. A bare "debian@sha256:..."
# has no tag for Dependabot to track, so it gets bumped against the full
# (non-slim) image (see reverted bump 0f10566: 1d3c811 -> 34cd9e9).
FROM debian:trixie-slim@sha256:d7e12182ce18b85b93007c1dedf31f2d29e01ccf3182cc4017c709b6259bc132 AS run
LABEL org.opencontainers.image.source=https://github.com/nam20485/OdbDesign \
org.opencontainers.image.authors=https://github.com/nam20485 \
org.opencontainers.image.description="A free open source cross-platform C++ library for parsing ODB++ Design archives and accessing their data. Exposed via a REST API (port 8888) and a gRPC API (port 50051) packaged inside of a Docker image. The OdbDesign Docker image runs the OdbDesignServer executable, which starts both servers in the same process and shares a single DesignCache." \
org.opencontainers.image.licenses=AGPL-3.0-only \
org.opencontainers.image.url=https://nam20485.github.io/OdbDesign \
org.opencontainers.image.documentation=https://github.com/nam20485/OdbDesign?tab=readme-ov-file \
org.opencontainers.image.title="OdbDesign Server"
EXPOSE 8888
EXPOSE 50051
# Docker health check using existing HTTP endpoint
HEALTHCHECK --interval=30s --timeout=3s --start-period=10s --retries=3 \
CMD curl -f http://localhost:8888/healthz/live || exit 1
# install runtime dependencies only
RUN apt-get update && \
apt-get install -y -q --no-install-recommends \
curl \
apt-transport-https \
ca-certificates \
p7zip-full \
&& \
apt-get clean && \
rm -rf /var/lib/apt/lists/*
# # --- gRPC health check (easy to disable: comment out the two blocks below) ---
# # Download grpc_health_probe binary
# RUN GRPC_HEALTH_PROBE_VERSION=v0.4.24 && \
# curl -sL -o /bin/grpc_health_probe \
# https://github.com/grpc-ecosystem/grpc-health-probe/releases/download/${GRPC_HEALTH_PROBE_VERSION}/grpc_health_probe-linux-amd64 && \
# chmod +x /bin/grpc_health_probe
# gRPC-specific healthcheck (comment out to disable, re-enable HTTP-only HEALTHCHECK above)
# HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
# CMD /bin/grpc_health_probe -addr=localhost:50051 || exit 1
# test 7z install
RUN 7z -h
# create non-root user
RUN groupadd --gid 10001 odbdesign && \
useradd --uid 10001 --gid odbdesign --create-home --shell /usr/sbin/nologin odbdesign
RUN mkdir --parents /OdbDesign/bin /OdbDesign/templates /OdbDesign/designs
WORKDIR /OdbDesign
# copy pre-built binaries from artifacts (extracted from zip in workflow)
# *.so* (not *.so): the linux-dynamic-release artifacts bundle versioned vcpkg
# shared libraries (e.g. libarchive.so.13, libprotobuf.so.33) alongside the
# project libraries; LD_LIBRARY_PATH=/OdbDesign/bin below makes them findable.
# The zip stores vcpkg's dev symlinks as symlinks (zip -y), so COPY recreates
# libfoo.so -> libfoo.so.N -> real-file chains as links, not duplicate copies.
COPY ./artifacts/*.so* ./bin/
# OpenSSL 3 provider modules (resolved relative to libcrypto.so's directory);
# mirrors the full Dockerfile's ossl-modules COPY
COPY ./artifacts/ossl-modules ./bin/ossl-modules
COPY ./artifacts/OdbDesignServer ./bin/
# gRPC service config (loaded by RunGrpcServer from exeDir/config.json)
COPY ./OdbDesignServer/config.json ./bin/config.json
# copy templates directory from source
COPY ./OdbDesignServer/templates/* ./templates/
# set ownership to non-root user
RUN chmod +x ./bin/OdbDesignServer && \
chown --recursive odbdesign:odbdesign /OdbDesign
USER odbdesign
# run
ENV LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/OdbDesign/bin
ENTRYPOINT [ "./bin/OdbDesignServer", "--designs-dir", "./designs", "--templates-dir", "./templates" ]