Files
plainleaf/Dockerfile.nas
T
wushenghuaandCodex 8ca2dc6539
CI / config (push) Canceled after 0s
CI / test-frontend (push) Canceled after 0s
CI / test-rust (push) Canceled after 0s
CI / test-e2e (push) Canceled after 0s
CI / test-e2e-release (push) Canceled after 0s
CI / build (push) Canceled after 0s
CI / release (push) Canceled after 0s
CI / docker (push) Canceled after 0s
CI / docker-website (push) Canceled after 0s
ops: cache pinned Rust target for NAS builds
Co-Authored-By: Codex <noreply@anthropic.com>
2026-08-12 16:52:28 +08:00

73 lines
2.7 KiB
Docker

# Build the customized Plainleaf client and Rust server for an amd64 NAS. Build
# stages run on the builder's native architecture; only the Rust output and
# final image target amd64. This keeps Apple Silicon cross-builds practical.
FROM --platform=$BUILDPLATFORM node:24.13.0-bookworm-slim AS client-builder
# The build script calls `git describe` and falls back to GITHUB_SHA when it
# exits non-zero. A tiny stub avoids installing Git into this disposable stage.
RUN printf '#!/bin/sh\nexit 1\n' > /usr/local/bin/git \
&& chmod +x /usr/local/bin/git
WORKDIR /src
COPY package.json package-lock.json ./
RUN npm ci
COPY . .
ARG GITHUB_SHA=unknown
RUN npm run build
FROM --platform=$BUILDPLATFORM rust:bookworm AS server-builder
ENV RUSTUP_DIST_SERVER=https://rsproxy.cn \
RUSTUP_UPDATE_ROOT=https://rsproxy.cn/rustup
RUN sed -i \
-e 's|http://deb.debian.org/debian|http://mirrors.aliyun.com/debian|g' \
-e 's|http://deb.debian.org/debian-security|http://mirrors.aliyun.com/debian-security|g' \
/etc/apt/sources.list.d/debian.sources \
&& apt-get update \
&& apt-get install -y --no-install-recommends \
gcc-x86-64-linux-gnu libc6-dev-amd64-cross \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
COPY rust-toolchain.toml ./
RUN rustup target add x86_64-unknown-linux-gnu
COPY . .
COPY --from=client-builder /src/client_bundle /src/client_bundle
COPY --from=client-builder /src/version.json /src/version.json
ENV CARGO_TARGET_X86_64_UNKNOWN_LINUX_GNU_LINKER=x86_64-linux-gnu-gcc \
CC_x86_64_unknown_linux_gnu=x86_64-linux-gnu-gcc
RUN printf '[source.crates-io]\nreplace-with = "rsproxy"\n\n[source.rsproxy]\nregistry = "sparse+https://rsproxy.cn/index/"\n' \
> /usr/local/cargo/config.toml
RUN --mount=type=cache,id=plainleaf-cargo-registry,target=/usr/local/cargo/registry \
--mount=type=cache,id=plainleaf-cargo-git,target=/usr/local/cargo/git \
--mount=type=cache,id=plainleaf-cargo-target,target=/src/target \
cargo build --locked --release -p silverbullet --target x86_64-unknown-linux-gnu \
&& x86_64-linux-gnu-strip target/x86_64-unknown-linux-gnu/release/silverbullet \
&& cp target/x86_64-unknown-linux-gnu/release/silverbullet /plainleaf
FROM debian:bookworm-slim
ENV SB_HOSTNAME=0.0.0.0 \
SB_FOLDER=/space \
SB_PORT=3000 \
SB_NAME=Plainleaf \
SB_DESCRIPTION="原生 Markdown 的中文个人知识库" \
SB_SHELL_BACKEND=off
COPY --from=server-builder /plainleaf /usr/local/bin/plainleaf
COPY --from=server-builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=5 \
CMD kill -0 1
ENTRYPOINT ["/usr/local/bin/plainleaf"]
CMD ["--single"]