Files
clawmates/images/broker.Dockerfile
T
Omar SobhandClaude Fable 5 8046853feb Post-1.0: OTLP tracing, broker image + compose service, install rehearsal
- tc-telemetry: fmt subscriber always; with [telemetry] otlp_endpoint
  set, spans batch-export over OTLP/HTTP. Tested against a REAL OTLP
  receiver decoding the actual protobuf (official proto types): the
  emitted span and service.name arrive on the wire. No endpoint = no
  export = no network (air-gap stance). tower-http TraceLayer gives
  every API request a span
- The broker finally has its own image (images/broker.Dockerfile,
  9.5MB from scratch) — the Helm chart referenced one that never
  existed — and the compose deployment now RUNS the broker, sharing a
  socket volume with the server (the unix-socket equivalent of the K8s
  sidecar). Compose secret flows were silently dead before this
- server.Dockerfile fixes surfaced by the rehearsal: the workspace
  build needs tools/ (bundler joined the workspace) and
  images/seccomp/ (include_str! profile) in the build context
- scripts/rehearse-install.sh (plan: clean-VM rehearsal): assembles a
  REAL signed bundle from the built images (server/frontend/broker/
  postgres/socket-proxy), runs the customer path — offline verify,
  docker load, compose up — and asserts /healthz plus the served login
  page before teardown. Passing locally; wired as a release.yml step,
  which also builds/ships the broker + socket-proxy images now

161 Rust tests + 29 journeys; clean-room rehearsal green.

Co-Authored-By: Claude Fable 5 <[email protected]>
2026-06-10 11:35:32 -05:00

27 lines
997 B
Docker

# The secret broker: its own minimal image, its own process boundary.
# Shares the builder pattern with the server image; ships ONLY the broker
# binary.
FROM rust:1-bookworm AS builder
RUN case "$(uname -m)" in \
aarch64) echo aarch64-unknown-linux-musl > /rust-target ;; \
*) echo x86_64-unknown-linux-musl > /rust-target ;; \
esac \
&& rustup target add "$(cat /rust-target)" \
&& apt-get update && apt-get install -y --no-install-recommends musl-tools \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
COPY Cargo.toml rust-toolchain.toml ./
COPY crates ./crates
COPY tools ./tools
COPY images/seccomp ./images/seccomp
COPY migrations ./migrations
COPY .sqlx ./.sqlx
ENV SQLX_OFFLINE=true
RUN cargo build --release --target "$(cat /rust-target)" -p teamclaw-broker \
&& cp "target/$(cat /rust-target)/release/teamclaw-broker" /teamclaw-broker
FROM scratch
COPY --from=builder /teamclaw-broker /teamclaw-broker
USER 10001:10001
ENTRYPOINT ["/teamclaw-broker"]