|
1 | | -# syntax = docker/dockerfile:1 |
| 1 | +# syntax=docker/dockerfile:1 |
2 | 2 |
|
3 | | -# This Dockerfile is designed for production, not development. Use with Kamal or build'n'run by hand: |
4 | | -# docker build -t my-app . |
5 | | -# docker run -d -p 80:80 -p 443:443 --name my-app -e RAILS_MASTER_KEY=<value from config/master.key> my-app |
| 3 | +ARG RUBY_VERSION |
| 4 | +FROM rubylang/ruby:$RUBY_VERSION-noble AS base |
6 | 5 |
|
7 | | -# For a containerized dev environment, see Dev Containers: https://guides.rubyonrails.org/getting_started_with_devcontainer.html |
8 | | - |
9 | | -# Make sure RUBY_VERSION matches the Ruby version in .ruby-version |
10 | | -ARG RUBY_VERSION=3.3.5 |
11 | | -FROM docker.io/library/ruby:$RUBY_VERSION-slim AS base |
12 | | - |
13 | | -# Rails app lives here |
14 | 6 | WORKDIR /rails |
15 | 7 |
|
16 | | -# Install base packages |
17 | | -RUN apt-get update -qq && \ |
18 | | - apt-get install --no-install-recommends -y curl libjemalloc2 postgresql-client && \ |
19 | | - apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* |
| 8 | +RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ |
| 9 | + --mount=type=cache,target=/var/lib/apt,sharing=locked \ |
| 10 | + <<EOF |
| 11 | + apt-get update -qq |
| 12 | + apt-get install --no-install-recommends -y libjemalloc2 sqlite3 |
| 13 | + ln -s /usr/lib/$(uname -m)-linux-gnu/libjemalloc.so.2 /usr/local/lib/libjemalloc.so |
| 14 | + rm -rf /var/lib/apt/lists /var/cache/apt/archives |
| 15 | +EOF |
20 | 16 |
|
21 | | -# Set production environment |
22 | 17 | ENV RAILS_ENV="production" \ |
23 | | - BUNDLE_WITHOUT="development:test:linters:deploy" \ |
24 | 18 | BUNDLE_DEPLOYMENT="1" \ |
25 | 19 | BUNDLE_PATH="/usr/local/bundle" \ |
26 | | - BUNDLE_WITHOUT="development" |
| 20 | + BUNDLE_WITHOUT="development:test" \ |
| 21 | + LD_PRELOAD="/usr/local/lib/libjemalloc.so" \ |
| 22 | + RUBYOPT="--enable-frozen-string-literal" |
| 23 | + |
27 | 24 |
|
28 | | -# Throw-away build stage to reduce size of final image |
29 | 25 | FROM base AS build |
30 | 26 |
|
31 | | -# Install packages needed to build gems |
32 | | -RUN apt-get update -qq && \ |
33 | | - apt-get install --no-install-recommends -y build-essential git pkg-config libpq-dev && \ |
34 | | - apt-get clean && rm -rf /var/cache/apt/archives /var/lib/apt/lists/* /tmp/* /var/tmp/* |
| 27 | +RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ |
| 28 | + --mount=type=cache,target=/var/lib/apt,sharing=locked \ |
| 29 | + apt-get update -qq && \ |
| 30 | + apt-get install --no-install-recommends -y build-essential git libssl-dev libyaml-dev pkg-config && \ |
| 31 | + rm -rf /var/lib/apt/lists /var/cache/apt/archives |
35 | 32 |
|
36 | | -# Install application gems |
37 | | -COPY Gemfile Gemfile.lock ./ |
38 | | -RUN bundle install && \ |
39 | | - rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git && \ |
40 | | - bundle exec bootsnap precompile --gemfile |
| 33 | +COPY --link Gemfile Gemfile.lock ./ |
| 34 | +RUN --mount=type=cache,target=/usr/local/bundle/cache \ |
| 35 | + <<EOF |
| 36 | + bundle install |
| 37 | + rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git |
| 38 | +EOF |
41 | 39 |
|
42 | | -# Copy application code |
43 | | -COPY . . |
| 40 | +COPY --link . . |
| 41 | + |
| 42 | +RUN <<EOF |
| 43 | + SECRET_KEY_BASE_DUMMY=1 ./bin/rails assets:precompile |
| 44 | + rm -rf app/assets |
| 45 | +EOF |
44 | 46 |
|
45 | | -RUN bundle exec bootsnap precompile app/ lib/ && \ |
46 | | - SECRET_KEY_BASE_DUMMY=1 ./bin/rails assets:precompile && \ |
47 | | - rm -rf vendor/ruby/3.3.0/cache |
48 | 47 |
|
49 | | -# Final stage for app image |
50 | 48 | FROM base |
51 | 49 |
|
52 | | -# Copy built artifacts: gems, application |
53 | | -COPY --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}" |
54 | | -COPY --from=build /rails /rails |
| 50 | +COPY --link --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}" |
| 51 | +COPY --link --from=build /rails /rails |
| 52 | + |
| 53 | +RUN <<EOF |
| 54 | + mkdir -p /data /rails/storage /hist |
| 55 | + chown -R ubuntu:ubuntu /data /hist /rails/db /rails/log /rails/storage /rails/tmp |
| 56 | +EOF |
55 | 57 |
|
56 | | -# Run and own only the runtime files as a non-root user for security |
57 | | -RUN groupadd --system --gid 1000 rails && \ |
58 | | - useradd rails --uid 1000 --gid 1000 --create-home --shell /bin/bash && \ |
59 | | - mkdir /data && \ |
60 | | - chown -R rails:rails db log storage tmp /data |
61 | | -USER 1000:1000 |
| 58 | +USER ubuntu |
62 | 59 |
|
63 | | -# Entrypoint prepares the database. |
64 | 60 | ENTRYPOINT ["/rails/bin/docker-entrypoint"] |
65 | 61 |
|
66 | | -# Start the server by default, this can be overwritten at runtime |
67 | 62 | EXPOSE 3000 |
68 | | -CMD ["./bin/rails", "server"] |
| 63 | +VOLUME /data |
| 64 | +VOLUME /hist |
| 65 | +CMD ["./bin/thrust", "./bin/rails", "server"] |
0 commit comments