check / check (push) Successful in 2m56s
Each config key can now be set by PIXA_ plus the key in upper case
("." written as "_"), and the port by PORT. One list pairs keys with
variables; the typed getters read a present variable, even an empty
one, before the config file, so every existing check covers it, and
errors a variable can reach name both the key and the variable. An
empty string for blocked_networks or trusted_proxies is now an empty
list, as for allowlist_hosts. The image no longer bakes in
config.docker.yml or passes --config; the config file is looked for
under /etc/pixa rather than /etc/pixad, so a file mounted at
/etc/pixa/config.yml is still read.
Model: opus-5-5
79 lines
1.9 KiB
Docker
79 lines
1.9 KiB
Docker
# Lint stage
|
|
# golangci/golangci-lint:v2.12.2-alpine, 2026-08-07
|
|
FROM golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804074a0bacea298707f016911e60cf0cdbc6c7bf5ccacb5f0606d18d60 AS lint
|
|
|
|
RUN apk add --no-cache make build-base vips-dev libheif-dev pkgconfig
|
|
|
|
WORKDIR /src
|
|
|
|
# Copy go mod files first for better layer caching
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
# Copy source code
|
|
COPY . .
|
|
|
|
# Run formatting check and linter
|
|
RUN make fmt-check
|
|
RUN make lint
|
|
|
|
# Build stage
|
|
# golang:1.25.4-alpine, 2026-02-25
|
|
FROM golang:1.25.4-alpine@sha256:d3f0cf7723f3429e3f9ed846243970b20a2de7bae6a5b66fc5914e228d831bbb AS builder
|
|
|
|
# Depend on lint stage passing
|
|
COPY --from=lint /src/go.sum /dev/null
|
|
|
|
ARG VERSION=dev
|
|
|
|
# Install build dependencies for CGO image libraries
|
|
RUN apk add --no-cache \
|
|
build-base \
|
|
vips-dev \
|
|
libheif-dev \
|
|
pkgconfig
|
|
|
|
WORKDIR /src
|
|
|
|
# Copy go mod files first for better layer caching
|
|
COPY go.mod go.sum ./
|
|
RUN GOTOOLCHAIN=auto go mod download
|
|
|
|
# Copy source code
|
|
COPY . .
|
|
|
|
# Run tests
|
|
RUN make test
|
|
|
|
# Build with CGO enabled
|
|
RUN CGO_ENABLED=1 GOTOOLCHAIN=auto go build -ldflags "-X main.Version=${VERSION}" -o /pixad ./cmd/pixad
|
|
|
|
# Runtime stage
|
|
# alpine:3.21, 2026-02-25
|
|
FROM alpine:3.21@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709
|
|
|
|
# Install runtime dependencies only
|
|
RUN apk add --no-cache \
|
|
vips \
|
|
libheif \
|
|
ca-certificates \
|
|
tzdata
|
|
|
|
# Copy binary from builder
|
|
COPY --from=builder /pixad /usr/local/bin/pixad
|
|
|
|
# Create non-root user, config directory, and data directory
|
|
RUN adduser -D -H -s /sbin/nologin pixad && \
|
|
mkdir -p /var/lib/pixa /etc/pixa && \
|
|
chown pixad:pixad /var/lib/pixa
|
|
|
|
USER pixad
|
|
WORKDIR /var/lib/pixa
|
|
|
|
EXPOSE 8080
|
|
|
|
# Settings come from PORT and the PIXA_ environment variables; only
|
|
# PIXA_SIGNING_KEY is required. A config file mounted at
|
|
# /etc/pixa/config.yml is optional and is read when present.
|
|
ENTRYPOINT ["/usr/local/bin/pixad"]
|