Some checks failed
build-and-release / build (companies) (push) Failing after 39s
build-and-release / build (catering-services) (push) Failing after 57s
build-and-release / build (cron) (push) Failing after 1m4s
build-and-release / build (gateway) (push) Successful in 3m46s
build-and-release / build (fitness-trainers) (push) Successful in 9m8s
build-and-release / build (graphic-designers) (push) Successful in 8m58s
build-and-release / build (employees) (push) Successful in 9m17s
build-and-release / build (customers) (push) Successful in 9m47s
build-and-release / build (developers) (push) Successful in 9m48s
build-and-release / build (job-seekers) (push) Successful in 9m1s
build-and-release / build (jobs) (push) Successful in 4m17s
build-and-release / build (leads) (push) Successful in 8m23s
build-and-release / build (makeup-artists) (push) Successful in 8m40s
build-and-release / build (payments) (push) Successful in 9m21s
build-and-release / build (photographers) (push) Successful in 9m20s
build-and-release / build (social-media-managers) (push) Successful in 8m9s
build-and-release / build (tutors) (push) Successful in 8m16s
build-and-release / build (ugc-content-creators) (push) Successful in 6m59s
build-and-release / build (video-editors) (push) Successful in 6m9s
build-and-release / build (users) (push) Successful in 8m37s
47 lines
1.5 KiB
Text
47 lines
1.5 KiB
Text
# Multi-service optimized Dockerfile with layer caching
|
|
# Usage: docker build --build-arg SERVICE_NAME=gateway -t nxtgauge-gateway .
|
|
|
|
# Stage 1: Base builder with dependencies cached
|
|
FROM ci.nxtgauge.com/admin/rust:alpine AS chef
|
|
RUN apk add --no-cache musl-dev pkgconfig openssl-dev ca-certificates && \
|
|
rustup target add x86_64-unknown-linux-musl && \
|
|
cargo install cargo-chef
|
|
WORKDIR /app
|
|
|
|
# Stage 2: Planner - analyzes dependencies
|
|
FROM chef AS planner
|
|
COPY Cargo.toml Cargo.lock ./
|
|
COPY crates/ ./crates/
|
|
COPY apps/ ./apps/
|
|
RUN cargo chef prepare --recipe-path recipe.json
|
|
|
|
# Stage 3: Builder - compiles dependencies separately (cached layer!)
|
|
FROM chef AS builder
|
|
ARG SERVICE_NAME
|
|
|
|
# Copy dependency recipe
|
|
COPY --from=planner /app/recipe.json recipe.json
|
|
|
|
# Build dependencies (cached if recipe.json unchanged)
|
|
RUN cargo chef cook --release --target x86_64-unknown-linux-musl --recipe-path recipe.json
|
|
|
|
# Copy source and build specific service
|
|
COPY Cargo.toml Cargo.lock ./
|
|
COPY crates/ ./crates/
|
|
COPY apps/ ./apps/
|
|
|
|
ENV RUSTFLAGS='-C target-feature=+crt-static'
|
|
RUN cargo build --release --bin ${SERVICE_NAME} --target x86_64-unknown-linux-musl
|
|
|
|
# Stage 4: Runtime - scratch image with local builder-provided certificates
|
|
FROM scratch
|
|
ARG SERVICE_NAME
|
|
|
|
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
|
|
COPY --from=builder /app/target/x86_64-unknown-linux-musl/release/${SERVICE_NAME} /app/service
|
|
|
|
USER 65532:65532
|
|
|
|
EXPOSE 8000
|
|
|
|
ENTRYPOINT ["/app/service"]
|