Files
clawmates/images/broker.Dockerfile
T
Omar Sobh 534eb72a95
ci / gates (push) Successful in 8s
ci / frontend (push) Successful in 2m11s
ci / rust (push) Failing after 3m17s
ci / e2e (push) Has been skipped
ci / publish (push) Failing after 3m21s
image(broker): install musl target AFTER rust-toolchain.toml is copied
Ordering matters. `rust:1.96-slim` ships with toolchain 1.96 already
installed under one identifier, but rust-toolchain.toml (channel = 1.96.0)
can prompt rustup to resolve to a distinct pinned toolchain. `rustup
target add` runs BEFORE rust-toolchain.toml lands, so it adds musl to the
wrong toolchain — cargo's later build picks up the workspace pin and can't
find core for the target. Move the COPY of rust-toolchain.toml before the
rustup target add so the target lands on the toolchain cargo actually
uses. Matches server.Dockerfile's known-working structure.
2026-07-05 16:12:24 -07:00

40 lines
1.8 KiB
Docker

# The secret broker: its own minimal image, its own process boundary.
# Shares the builder pattern with the server image; ships ONLY the broker
# binary.
FROM rust:1.96-slim AS builder
ARG TARGETARCH
# git + cmake are needed for the clawhdf5 git dependency (fetched via the git
# CLI — libgit2 chokes on Gitea smart-HTTP) and its zlib-ng C build (cmake).
RUN apt-get update \
&& apt-get install -y --no-install-recommends musl-tools git cmake make pkg-config \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /src
COPY Cargo.toml Cargo.lock rust-toolchain.toml ./
COPY crates ./crates
COPY tools ./tools
COPY images/seccomp ./images/seccomp
COPY migrations ./migrations
COPY .sqlx ./.sqlx
# Install the musl target AFTER rust-toolchain.toml is in place, so rustup adds
# it to the toolchain the workspace pins (channel 1.96.0), not the base image's
# default. Doing this before the COPY installs into a toolchain cargo won't
# actually use, and the build then fails with E0463 (no core for musl).
RUN case "$TARGETARCH" in \
arm64) echo aarch64-unknown-linux-musl > /rust-target ;; \
*) echo x86_64-unknown-linux-musl > /rust-target ;; \
esac \
&& rustup target add "$(cat /rust-target)"
ENV SQLX_OFFLINE=true
# Fetch git deps with the system git (libgit2 fails against Gitea smart-HTTP);
# build the zlib-ng C dep with the musl cross compiler for the static target.
ENV CARGO_NET_GIT_FETCH_WITH_CLI=true \
CC_x86_64_unknown_linux_musl=musl-gcc \
CC_aarch64_unknown_linux_musl=musl-gcc
RUN cargo build --release --target "$(cat /rust-target)" -p clawmates-broker \
&& cp "target/$(cat /rust-target)/release/clawmates-broker" /clawmates-broker
FROM scratch
COPY --from=builder /clawmates-broker /clawmates-broker
USER 10001:10001
ENTRYPOINT ["/clawmates-broker"]