build: Dockerfile non-root user, healthcheck, .dockerignore

This commit is contained in:
clawbot 2026-02-11 00:50:13 -08:00
parent eefb81ed8d
commit 1aac9cf480
2 changed files with 13 additions and 8 deletions

View File

@ -1,8 +1,9 @@
bin/
chatd
data.db
.env
.git
*.test
*.out
debug.log
*.md
!README.md
chatd
chat-cli
data.db
data.db-wal
data.db-shm
.env

View File

@ -18,8 +18,12 @@ RUN CGO_ENABLED=1 go build -trimpath -ldflags="-s -w" -o /chat-cli ./cmd/chat-cl
# Final stage — server only
FROM alpine:3.21
RUN apk add --no-cache ca-certificates
RUN apk add --no-cache ca-certificates \
&& addgroup -S chat && adduser -S chat -G chat
COPY --from=builder /chatd /usr/local/bin/chatd
USER chat
EXPOSE 8080
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD wget -qO- http://localhost:8080/.well-known/healthcheck.json || exit 1
ENTRYPOINT ["chatd"]