ops: add ZSpace NAS deployment
CI / config (push) Canceled after 0s
CI / test-frontend (push) Canceled after 0s
CI / test-rust (push) Canceled after 0s
CI / test-e2e (push) Canceled after 0s
CI / test-e2e-release (push) Canceled after 0s
CI / build (push) Canceled after 0s
CI / release (push) Canceled after 0s
CI / docker (push) Canceled after 0s
CI / docker-website (push) Canceled after 0s

This commit is contained in:
2026-08-12 12:40:04 +08:00
parent 94d310d712
commit 0ff820bae3
3 changed files with 109 additions and 0 deletions
+42
View File
@@ -0,0 +1,42 @@
# Build the customized Plainleaf client and Rust server for an amd64 NAS.
FROM node:24.13.0-bookworm-slim AS client-builder
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates git \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
COPY . .
ARG GITHUB_SHA=unknown
RUN npm ci \
&& npm run build
FROM rust:bookworm AS server-builder
WORKDIR /src
COPY --from=client-builder /src /src
RUN cargo build --locked --release -p silverbullet \
&& strip target/release/silverbullet
FROM debian:bookworm-slim
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates curl git openssh-client tini \
&& rm -rf /var/lib/apt/lists/*
ENV SB_HOSTNAME=0.0.0.0 \
SB_FOLDER=/space \
SB_PORT=3000 \
SB_NAME=Plainleaf \
SB_SHELL_BACKEND=off
COPY --from=server-builder /src/target/release/silverbullet /usr/local/bin/plainleaf
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=5 \
CMD curl --fail "http://127.0.0.1:${SB_PORT}/.instance" || exit 1
ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/plainleaf"]
CMD ["--single"]
+26
View File
@@ -0,0 +1,26 @@
# Plainleaf on ZSpace NAS
This deployment builds the customized Plainleaf source on an amd64 ZSpace NAS.
It keeps deployment files and Markdown data separate:
- Deployment: `个人空间/docker/plainleaf`
- Markdown space: `个人空间/笔记管理/Plainleaf`
The server listens on NAS port `3000`, runs as the NAS account's UID/GID, and
has SilverBullet shell execution disabled. Authentication is supplied through a
deployment-local `.env` file that must not be committed.
The intended `.env` keys are:
```dotenv
PLAINLEAF_GIT_SHA=94d310d71211de57339724a9ad5cb21f214e101a
PLAINLEAF_IMAGE_TAG=94d310d7
PLAINLEAF_UID=1001
PLAINLEAF_GID=1001
PLAINLEAF_PORT=3000
PLAINLEAF_SPACE_PATH=/tmp/zfsv3/sata11/13616066635/data/笔记管理/Plainleaf
PLAINLEAF_USER=your-user:your-password
```
Do not commit the real `.env` file. Do not expose the service publicly until a
separate HTTPS reverse-proxy configuration has been verified.
+41
View File
@@ -0,0 +1,41 @@
name: plainleaf
services:
plainleaf:
build:
context: ../..
dockerfile: Dockerfile.nas
args:
GITHUB_SHA: ${PLAINLEAF_GIT_SHA:-unknown}
image: plainleaf:${PLAINLEAF_IMAGE_TAG:-local}
container_name: plainleaf
restart: unless-stopped
user: "${PLAINLEAF_UID:-1001}:${PLAINLEAF_GID:-1001}"
environment:
SB_HOSTNAME: 0.0.0.0
SB_PORT: 3000
SB_FOLDER: /space
SB_NAME: Plainleaf
SB_USER: ${PLAINLEAF_USER:?Set PLAINLEAF_USER in the NAS deployment .env file}
SB_SHELL_BACKEND: "off"
ports:
- "${PLAINLEAF_PORT:-3000}:3000"
volumes:
- "${PLAINLEAF_SPACE_PATH:?Set PLAINLEAF_SPACE_PATH in the NAS deployment .env file}:/space"
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
init: false
healthcheck:
test: ["CMD", "curl", "--fail", "http://127.0.0.1:3000/.instance"]
interval: 30s
timeout: 5s
start_period: 20s
retries: 5
networks:
- plainleaf
networks:
plainleaf:
name: plainleaf_network