-
-
Notifications
You must be signed in to change notification settings - Fork 186
Expand file tree
/
Copy pathDockerfile
More file actions
189 lines (136 loc) · 5.16 KB
/
Copy pathDockerfile
File metadata and controls
189 lines (136 loc) · 5.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
# Stage 1: go-base
FROM golang:1.27.0-alpine AS go-base
HEALTHCHECK NONE
# package version does not matter
# trunk-ignore(hadolint/DL3018)
RUN apk add --no-cache tzdata libcap-setcap
ARG SHADOWTREE_VERSION=latest
RUN --mount=type=cache,target=/root/.cache/go-build \
--mount=type=cache,target=/root/go/pkg/mod \
CGO_ENABLED=0 go install github.com/yusing/shadowtree/cmd/shadowtree@${SHADOWTREE_VERSION}
# Stage 2: frontend-base
FROM go-base AS frontend-base
# libgcc and libstdc++ are needed for bun
# trunk-ignore(hadolint/DL3018)
RUN apk add --no-cache libgcc libstdc++
# for minify and webui build
COPY --from=oven/bun:1-alpine /usr/local/bin/bun /usr/local/bin/bun
COPY --from=oven/bun:1-alpine /usr/local/bin/bunx /usr/local/bin/bunx
COPY --from=node:lts-alpine3.22 /usr/local/bin/node /usr/local/bin/node
COPY --from=node:lts-alpine3.22 /usr/local/bin/npm /usr/local/bin/npm
# Stage 3: godoxy deps
FROM go-base AS godoxy-deps
ENV GOPATH=/root/go
ENV GOCACHE=/root/.cache/go-build
WORKDIR /src
COPY goutils/go.mod goutils/go.sum ./goutils/
COPY internal/go-oidc/go.mod internal/go-oidc/go.sum ./internal/go-oidc/
COPY internal/gopsutil/go.mod internal/gopsutil/go.sum ./internal/gopsutil/
COPY go.mod go.sum ./
# remove godoxy stuff from go.mod first
RUN --mount=type=cache,target=/root/.cache/go-build \
--mount=type=cache,target=/root/go/pkg/mod \
sed -i '/^module github\.com\/yusing\/godoxy/!{/github\.com\/yusing\/godoxy/d}' go.mod && \
sed -i '/^module github\.com\/yusing\/goutils/!{/github\.com\/yusing\/goutils/d}' go.mod && \
go mod download -x
# Stage 4: webui deps
FROM frontend-base AS webui-deps
WORKDIR /src
COPY webui/package.json webui/bun.lock ./
RUN bun install --frozen-lockfile
# Stage 5: webui schema generation
FROM frontend-base AS webui-schema
WORKDIR /src
COPY webui/src/types/godoxy/ ./src/types/godoxy/
COPY webui/.shadowtree.toml ./.shadowtree.toml
COPY webui/tsconfig.json ./tsconfig.json
RUN --mount=type=cache,target=/root/.bun shadowtree gen-schema
# Stage 6: webui build
FROM frontend-base AS webui-build
WORKDIR /src
COPY --from=webui-deps /src/node_modules ./node_modules
COPY webui .
COPY --from=webui-schema /src/src/types/godoxy/*.json ./src/types/godoxy/
ENV NODE_ENV=production
RUN node ./node_modules/vite/bin/vite.js build
# Stage 7: binary source
FROM godoxy-deps AS binary-source
WORKDIR /src
COPY scripts/minify ./scripts/minify
COPY go.mod go.sum ./
COPY .shadowtree.toml ./
COPY .shadowtree/benchmark.toml ./.shadowtree/benchmark.toml
COPY cmd ./cmd
COPY internal ./internal
COPY pkg ./pkg
COPY agent ./agent
COPY socket-proxy ./socket-proxy
COPY goutils ./goutils
ARG VERSION
ENV VERSION=${VERSION}
ARG BRANCH
ENV BRANCH=${BRANCH}
ENV GOPATH=/root/go
ENV GOCACHE=/root/.cache/go-build
# Stage 8: agent builder
FROM binary-source AS agent-builder
ARG SHADOWTREE_ARGS="component=agent"
RUN --mount=type=cache,target=/root/.cache/go-build \
--mount=type=cache,target=/root/go/pkg/mod \
shadowtree build ${SHADOWTREE_ARGS} docker=true
# Stage 9: socket proxy builder
FROM binary-source AS socket-proxy-builder
ARG SHADOWTREE_ARGS="component=socket-proxy"
RUN --mount=type=cache,target=/root/.cache/go-build \
--mount=type=cache,target=/root/go/pkg/mod \
shadowtree build ${SHADOWTREE_ARGS} docker=true
# Stage 10: main builder
FROM binary-source AS main-builder
# libgcc and libstdc++ are needed for bun
# trunk-ignore(hadolint/DL3018)
RUN apk add --no-cache libgcc libstdc++
COPY --from=oven/bun:1-alpine /usr/local/bin/bun /usr/local/bin/bun
COPY --from=oven/bun:1-alpine /usr/local/bin/bunx /usr/local/bin/bunx
COPY --from=node:lts-alpine3.22 /usr/local/bin/node /usr/local/bin/node
COPY --from=node:lts-alpine3.22 /usr/local/bin/npm /usr/local/bin/npm
COPY webui/embed.go ./webui/embed.go
COPY webui/embed_dev.go ./webui/embed_dev.go
COPY --from=webui-build /src/dist/client ./webui/dist/client
ARG SHADOWTREE_ARGS="component=godoxy"
RUN --mount=type=cache,target=/root/.cache/go-build \
--mount=type=cache,target=/root/go/pkg/mod \
shadowtree build ${SHADOWTREE_ARGS} docker=true
# Stage 11: agent image
FROM scratch AS agent
LABEL maintainer="yusing@6uo.me"
LABEL proxy.exclude=1
LABEL proxy.#1.healthcheck.disable=true
COPY --from=agent-builder /usr/share/zoneinfo /usr/share/zoneinfo
COPY --from=agent-builder /app/run /app/run
COPY --from=agent-builder /etc/ssl/certs /etc/ssl/certs
ENV DOCKER_HOST=unix:///var/run/docker.sock
WORKDIR /app
CMD ["/app/run"]
# Stage 12: socket proxy image
FROM scratch AS socket-proxy
LABEL maintainer="yusing@6uo.me"
LABEL proxy.exclude=1
LABEL proxy.#1.healthcheck.disable=true
COPY --from=socket-proxy-builder /usr/share/zoneinfo /usr/share/zoneinfo
COPY --from=socket-proxy-builder /app/run /app/run
COPY --from=socket-proxy-builder /etc/ssl/certs /etc/ssl/certs
ENV LISTEN_ADDR=0.0.0.0:2375
WORKDIR /app
CMD ["/app/run"]
# Stage 13: main image
FROM scratch AS main
LABEL maintainer="yusing@6uo.me"
LABEL proxy.exclude=1
LABEL proxy.#1.healthcheck.disable=true
COPY --from=main-builder /usr/share/zoneinfo /usr/share/zoneinfo
COPY --from=main-builder /app/run /app/run
COPY --from=main-builder /etc/ssl/certs /etc/ssl/certs
ENV DOCKER_HOST=unix:///var/run/docker.sock
ENV HOME=/app
WORKDIR /app
CMD ["/app/run"]