Files
mangaBookmark/backend/Dockerfile
T
sulthan c55a1de354 build: bump to Go 1.24 and add bogdanfinn/tls-client
tls-client v1.15.1 declares go 1.24.1; every release back to v1.13.0
does the same, so the 1.23 floor cannot stay. Pure Go, so the
CGO_ENABLED=0 static build and distroless image are unchanged.
2026-07-26 15:26:08 +07:00

36 lines
1.1 KiB
Docker

# syntax=docker/dockerfile:1
# --- build stage: compile a static, CGO-free binary ---
FROM golang:1.24-alpine AS build
WORKDIR /src
# Dependencies first for layer caching (changes rarely).
COPY go.mod go.sum ./
RUN go mod download
# Then source (changes often).
# Source plus the go:embed'd assets. Missing either directory turns the embed
# directive into a build error, so both must be copied before `go build`.
COPY *.go ./
COPY templates/ ./templates/
COPY static/ ./static/
# Static binary: pure-Go sqlite means CGO_ENABLED=0 -> no libc dependency.
# -trimpath + -ldflags strip paths and debug info for a smaller image.
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-s -w" -o /out/server .
# Data dir with the runtime user's ownership so the mounted volume inherits it.
RUN mkdir -p /out/data
# --- runtime stage: distroless static, non-root ---
FROM gcr.io/distroless/static:nonroot
WORKDIR /
COPY --from=build /out/server /server
COPY --from=build --chown=65532:65532 /out/data /data
VOLUME ["/data"]
EXPOSE 8080
USER nonroot:nonroot
ENV DB_PATH=/data/bookmarks.db PORT=8080
ENTRYPOINT ["/server"]