Files
ngit-grasp/Dockerfile
T
DanConwayDev 5fed50e5e3 ci(release): publish OCI container images
Motivation: Release images should be built, checked, published, and consumed through the same Nostr-native OCI path operators will use, without relying on an unreviewed local release procedure.

Approach: Add a checked-in container manifest, a Docker-to-OCI layout helper, automatic tag publication and pull verification, a safe exact-tag backfill workflow, and deployment CI that imports and runs the exact generated layout.

Correctness: Release tags come only from reviewed OCI index annotations; ordinary publication preserves prior tags; historical backfills cannot move latest or prerelease channels; generated images and temporary resources use bounded, validated names and cleanup.

Excluded scope: This change does not alter ngit-grasp runtime behavior, change package versions, create v3.0.2, publish a container, move a release tag, or run the heavyweight container build in the coding VM.

Validation: git diff --check; shellcheck on all container scripts; actionlint on all affected workflows; ngit parsing of .ngit/containers.yaml; canonical source and v3.0.1 tag resolution. The PR pipeline performs the full OCI build, import, and deployment test.

Assisted-by: Codex (GPT-5)
2026-09-10 15:30:13 +00:00

56 lines
1.6 KiB
Docker

# syntax=docker/dockerfile:1
FROM rust:1.96-bookworm AS builder
RUN apt-get update \
&& apt-get install -y --no-install-recommends libssl-dev pkg-config \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
COPY . .
ARG NGIT_BUILD_REVISION=unknown
ENV NGIT_BUILD_REVISION=${NGIT_BUILD_REVISION}
RUN cargo build --locked --release -p ngit-grasp
FROM debian:bookworm-slim AS runtime
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
ca-certificates \
curl \
git \
gosu \
libssl3 \
tini \
&& rm -rf /var/lib/apt/lists/* \
&& groupadd --system --gid 10001 ngit-grasp \
&& useradd --system --uid 10001 --gid ngit-grasp \
--home-dir /data --no-create-home ngit-grasp \
&& install -d -m 0750 -o ngit-grasp -g ngit-grasp \
/data /data/git /data/relay
COPY --from=builder /src/target/release/ngit-grasp /usr/local/bin/ngit-grasp
COPY deploy/docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
ARG NGIT_IMAGE_VERSION=dev
ARG NGIT_IMAGE_REVISION=unknown
LABEL org.opencontainers.image.title="ngit-grasp" \
org.opencontainers.image.description="GRASP relay and Git Smart HTTP server" \
org.opencontainers.image.licenses="MIT" \
org.opencontainers.image.source="https://ngit.dev/ngit-grasp.git" \
org.opencontainers.image.version="${NGIT_IMAGE_VERSION}" \
org.opencontainers.image.revision="${NGIT_IMAGE_REVISION}"
ENV HOME=/data \
NGIT_GIT_DATA_PATH=/data/git \
NGIT_RELAY_DATA_PATH=/data/relay
WORKDIR /data
VOLUME ["/data"]
EXPOSE 7334
STOPSIGNAL SIGTERM
ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/docker-entrypoint.sh"]