A SimpleX Chat bot that answers arithmetic (closes #1)
check / check (push) Successful in 54s
check / check (push) Successful in 54s
Remove the template's HTTP service, database and fx wiring. Add exact arithmetic on go/parser and go/constant, a client that runs simplex-chat as a child process and drives its WebSocket API, and the bot, which keeps an auto-accepting address and replies to each message. The image adds the checksum-pinned simplex-chat v7.0.2 on Ubuntu 22.04. Model: opus-5-5
This commit is contained in:
+26
-18
@@ -71,8 +71,7 @@ RUN go test -count=1 -timeout 90s -race -cover ./... || \
|
||||
{ echo "--- Rerunning with -v for details ---"; \
|
||||
go test -count=1 -timeout 90s -race -v ./...; exit 1; }
|
||||
|
||||
# Static build; modernc.org/sqlite is pure Go, so CGO_ENABLED=0 yields
|
||||
# a fully static binary that runs on the Alpine runtime.
|
||||
# Static build, so the binary runs on any runtime base.
|
||||
ARG VERSION=dev
|
||||
RUN CGO_ENABLED=0 go build -trimpath \
|
||||
-ldflags "-s -w -X main.version=${VERSION}" \
|
||||
@@ -82,33 +81,42 @@ RUN CGO_ENABLED=0 go build -trimpath \
|
||||
# BuildKit builds whichever stage is last and appending one drops lint,
|
||||
# builder and their checks out of the run. Nothing asserts the name; it
|
||||
# is here so that failure reads as `[runtime n/m]` in the build log.
|
||||
# alpine:3.22, 2026-08-07
|
||||
FROM alpine:3.22@sha256:14358309a308569c32bdc37e2e0e9694be33a9d99e68afb0f5ff33cc1f695dce AS runtime
|
||||
# Ubuntu 22.04 because it is the release the SimpleX Chat client below
|
||||
# is built for, and it already has every library that client links
|
||||
# (glibc, OpenSSL 3, GMP, zlib), so nothing is installed on top.
|
||||
# ubuntu:22.04, 2026-09-26
|
||||
FROM ubuntu:22.04@sha256:b8b6ee6aa931ecd9d0d952abc34dc0e5f7c6a30c6bb71b079fe399fde0329c02 AS runtime
|
||||
|
||||
RUN apk --no-cache add ca-certificates
|
||||
# The SimpleX Chat command-line client, which the bot starts and talks
|
||||
# to. BuildKit checks the download against the checksum and fails the
|
||||
# build on a mismatch; a new release means changing both the URL and
|
||||
# the checksum. This is the x86_64 build, so the image is x86_64 only;
|
||||
# an arm64 image would need the aarch64 build and its own checksum.
|
||||
# simplex-chat v7.0.2 (simplex-chat-ubuntu-22_04-x86_64), 2026-09-26
|
||||
ADD --chmod=0755 \
|
||||
--checksum=sha256:5afb1d25efe5ccf564a1ab124bc7f410a7a73171c974a4d8b7f4d8f2e3d62e77 \
|
||||
https://github.com/simplex-chat/simplex-chat/releases/download/v7.0.2/simplex-chat-ubuntu-22_04-x86_64 \
|
||||
/usr/local/bin/simplex-chat
|
||||
|
||||
# Create non-root user
|
||||
RUN addgroup -g 1000 -S simplexcalc && \
|
||||
adduser -u 1000 -S simplexcalc -G simplexcalc
|
||||
RUN groupadd --gid 1000 simplexcalc && \
|
||||
useradd --uid 1000 --gid simplexcalc --home-dir /var/lib/simplexcalc \
|
||||
--no-create-home --shell /usr/sbin/nologin simplexcalc
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Copy binary from builder
|
||||
COPY --from=builder /build/bin/simplexcalc /app/simplexcalc
|
||||
|
||||
# Data directory: the sqlite database lives here. Mount a volume over
|
||||
# it in production; everything else in the image is read-only.
|
||||
RUN mkdir -p /var/lib/simplexcalc
|
||||
|
||||
RUN chown -R simplexcalc:simplexcalc /app /var/lib/simplexcalc
|
||||
# Data directory: the SimpleX database, which holds the bot's profile,
|
||||
# its keys, its address and its contacts. Mount a volume over it;
|
||||
# without one, the bot gets a new address every time the container is
|
||||
# recreated.
|
||||
RUN mkdir -p /var/lib/simplexcalc && \
|
||||
chown simplexcalc:simplexcalc /var/lib/simplexcalc
|
||||
|
||||
USER simplexcalc
|
||||
|
||||
ENV DATA_DIR=/var/lib/simplexcalc
|
||||
|
||||
EXPOSE 8080
|
||||
|
||||
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
|
||||
CMD wget --no-verbose --tries=1 --spider http://localhost:8080/.well-known/healthcheck.json || exit 1
|
||||
|
||||
CMD ["/app/simplexcalc", "serve"]
|
||||
CMD ["/app/simplexcalc", "run"]
|
||||
|
||||
Reference in New Issue
Block a user