Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@
# deploy/k3s/dev-push.sh loop. Only the five kloudlite binaries make it into the context — see
# .dockerignore — so a fat `target/` costs nothing to send.

FROM debian:bookworm-slim@sha256:abd67ffcfa541b485a3dff59865ab629aa048a6c613e639d36e7456b0b229241 AS server
FROM debian:bookworm-slim@sha256:88200866dfff7ea7f5cbcb6ec7c8a701889efe6fe859fe64d6990e4b07ea4171 AS server
# openssh-client: the server shells out to ssh-keygen to generate its host key on first start.
# git: the merge worker performs merges by running it (see crates/pulls/src/merge_worker.rs) —
# bookworm ships 2.39, past the 2.38 that `merge-tree --write-tree` needs. One image serves all
Expand Down Expand Up @@ -53,7 +53,7 @@ CMD ["serve"]
# The node controller. A separate IMAGE, not a fourth binary in the server one: this runs as root
# with btrfs-progs and the host pool mounted, and shipping root's toolchain to the three processes
# that must never have it is exactly what the split prevents.
FROM debian:bookworm-slim@sha256:abd67ffcfa541b485a3dff59865ab629aa048a6c613e639d36e7456b0b229241 AS agent
FROM debian:bookworm-slim@sha256:88200866dfff7ea7f5cbcb6ec7c8a701889efe6fe859fe64d6990e4b07ea4171 AS agent
# btrfs-progs: every storage operation shells out to it.
# util-linux: losetup/mount for the block-layer restore path.
# ca-certificates: the registry client and Azure blob store speak TLS.
Expand Down Expand Up @@ -81,7 +81,7 @@ ENTRYPOINT ["kloudlite-agent"]
# The SSH gateway. Its own image rather than a fourth binary in the server one: this pod runs with
# NET_BIND_SERVICE to hold hostPort 443 on a pool node, and that capability has no business on the
# git server's pods.
FROM debian:bookworm-slim@sha256:abd67ffcfa541b485a3dff59865ab629aa048a6c613e639d36e7456b0b229241 AS gateway
FROM debian:bookworm-slim@sha256:88200866dfff7ea7f5cbcb6ec7c8a701889efe6fe859fe64d6990e4b07ea4171 AS gateway
# ca-certificates only: the gateway talks to the kube API server over TLS and to nothing else.
# libcap2-bin is build-time only, for the setcap below.
RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates libcap2-bin \
Expand All @@ -104,7 +104,7 @@ ENTRYPOINT ["kloudlite-gateway"]

# The build gate. Its own image for the same reason the gateway has one: a different pod, a
# different ServiceAccount, and no reason for the git server's pods to carry either binary.
FROM debian:bookworm-slim@sha256:abd67ffcfa541b485a3dff59865ab629aa048a6c613e639d36e7456b0b229241 AS builder-gate
FROM debian:bookworm-slim@sha256:88200866dfff7ea7f5cbcb6ec7c8a701889efe6fe859fe64d6990e4b07ea4171 AS builder-gate
# ca-certificates only: the gate talks TLS to the kube API server and to the api tier's public
# URL, and plain TCP to buildkit.
RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates \
Expand Down Expand Up @@ -135,7 +135,7 @@ ENTRYPOINT ["kloudlite-builder-gate"]
# Pinned by digest like every other stage (2026-09-12 review #69): a tag is a pointer Docker Hub
# can move, and this is the image a person's whole working day runs inside. Looked up 2026-09-12
# with the same recipe as nixos/nix in deploy/k3s/agent-daemonset.yaml; the tag stays for humans.
FROM alpine:3.20@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc AS workspace
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS workspace
ARG PROFILE=release
RUN apk add --no-cache libstdc++ libgcc docker-cli docker-cli-buildx nodejs npm \
&& mkdir -p /var/empty \
Expand Down Expand Up @@ -177,7 +177,7 @@ ENV DO_NOT_TRACK=1
# The SLO probe. Its own image because it is the only one that carries a toolbox — git, ssh,
# crane, kubectl, dig, openssl — and shipping that to the three server processes would hand a
# compromised request handler everything it needs to talk to the cluster.
FROM debian:bookworm-slim@sha256:abd67ffcfa541b485a3dff59865ab629aa048a6c613e639d36e7456b0b229241 AS slo
FROM debian:bookworm-slim@sha256:88200866dfff7ea7f5cbcb6ec7c8a701889efe6fe859fe64d6990e4b07ea4171 AS slo
# git + openssh-client: stage 2 pushes and clones over both transports, with a real client, because
# a probe that used our own library would pass on a bug only a real client trips.
# curl is the build-time tool fetch below; the edge stage dials the origin with reqwest.
Expand Down
6 changes: 3 additions & 3 deletions web/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,13 @@
# package is visible.

# 1.3.14 exactly, matching CI's setup-bun, so the lockfile is read by one bun everywhere.
FROM oven/bun:1.3.14@sha256:e10577f0db68676a7024391c6e5cb4b879ebd17188ab750cf10024a6d700e5c4 AS bun
FROM oven/bun:1.4.2@sha256:9114c058aeae42162ee16dd5084b95fe9473970bb6bcb5b232ab1630f0546895 AS bun

# Node, with bun copied in. bun installs (it owns the lockfile) but does not run
# the build: `next build` under bun's runtime dies with SIGILL on GitHub's
# runners, while the same build under node is fine — which is what CI's check
# job does too.
FROM node:22-bookworm-slim@sha256:d649c27dae7ba0137b3cef5dd75baa422c08dc3d9e3fc0c23dfb172dc3cc6436 AS deps
FROM node:26-bookworm-slim@sha256:cd9f682fa2885cd1056e830424764158570061c59736a1da836bc3d73df095ae AS deps
COPY --from=bun /usr/local/bin/bun /usr/local/bin/bun
WORKDIR /src
# The whole workspace at once, not a hand-listed set of manifests: that would
Expand All @@ -28,7 +28,7 @@ RUN node node_modules/next/dist/bin/next build apps/web

# Same libc as the build stage: the standalone output carries native modules
# (sharp, shiki's oniguruma) compiled against it.
FROM node:22-bookworm-slim@sha256:d649c27dae7ba0137b3cef5dd75baa422c08dc3d9e3fc0c23dfb172dc3cc6436 AS run
FROM node:26-bookworm-slim@sha256:cd9f682fa2885cd1056e830424764158570061c59736a1da836bc3d73df095ae AS run
WORKDIR /app
ENV NODE_ENV=production NEXT_TELEMETRY_DISABLED=1 PORT=3000 HOSTNAME=0.0.0.0
RUN useradd --system --create-home --uid 1001 app
Expand Down
Loading