30 lines
1.3 KiB
Docker
30 lines
1.3 KiB
Docker
# Runtime image for zfin-vestwell.
|
|
#
|
|
# Single stage on `scratch`, matching zfin and zfin-server: the Zig build runs in
|
|
# CI, produces a statically-linked musl binary, and the workflow drops it into
|
|
# this directory before `docker build`. There is no toolchain in the image and no
|
|
# network needed at image-build time.
|
|
#
|
|
# The CA bundle is mandatory, not optional cruft. `record` fetches the plan's feed
|
|
# over HTTPS, and Zig's certificate loader scans a fixed list of host paths
|
|
# (std/crypto/Certificate/Bundle.zig) of which `/etc/ssl/certs/ca-certificates.crt`
|
|
# is the Debian/Ubuntu one. `scratch` has no CA store at all, so without this the
|
|
# TLS handshake fails.
|
|
FROM scratch
|
|
COPY ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
|
|
COPY zfin-vestwell /zfin-vestwell
|
|
|
|
# Bare ENTRYPOINT, following zfin rather than zfin-server: the subcommand varies
|
|
# per invocation (`record` then `assemble`), so it cannot be baked in.
|
|
#
|
|
# WORKDIR is the data mount, so `--data-dir` can be omitted when the caller mounts
|
|
# the repo's data/ directory at /data.
|
|
WORKDIR /data
|
|
|
|
# Numeric uid:gid is the only form that can work here -- `scratch` has no
|
|
# /etc/passwd for a name to resolve against. 1000:1000 is what owns the
|
|
# syncthing-mirrored data directory and the zfin cache on the NAS, and this
|
|
# process writes to both.
|
|
USER 1000:1000
|
|
|
|
ENTRYPOINT ["/zfin-vestwell"]
|