Stage-0 web UI needs a self-contained container image. Two changes: - Dockerfile: multi-stage build (golang:1.25 builder, CGO off + static link, -trimpath -s -w) into distroless static nonroot. The committed templ output and vendored asset mean a plain `go build` suffices — no codegen or CDN at build/run time. Existing .gitea CI already builds and pushes localhost:5000/tapir:<sha> + mirrors to GitHub (deploy patch intentionally omitted — cutover is held), so it only needed this file. - Vendor htmx 1.9.12 locally (internal/web/static/, embed.FS, served at /static/ outside the auth guard) and point Layout at /static/htmx.min.js instead of unpkg. The deployed UI must not depend on an external CDN being reachable from the cluster. task check green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
30 lines
1.2 KiB
Docker
30 lines
1.2 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# ── build ───────────────────────────────────────────────────────────────────
|
|
# templ output (*_templ.go) and the vendored htmx asset are committed, so a
|
|
# plain `go build` produces a self-contained binary — no codegen, no CDN.
|
|
FROM golang:1.25 AS build
|
|
|
|
WORKDIR /src
|
|
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
# CGO off + static linking so the binary runs in a distroless/scratch image with
|
|
# no libc. Trim symbols/DWARF to shrink the layer.
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags='-s -w' -o /out/tapir ./cmd/tapir
|
|
|
|
# ── runtime ─────────────────────────────────────────────────────────────────
|
|
# distroless static + nonroot: no shell, no package manager, runs as uid 65532.
|
|
# ca-certificates are bundled, which the OIDC/HTTPS clients need.
|
|
FROM gcr.io/distroless/static-debian12:nonroot
|
|
|
|
COPY --from=build /out/tapir /tapir
|
|
|
|
EXPOSE 8080
|
|
USER nonroot:nonroot
|
|
ENTRYPOINT ["/tapir"]
|
|
CMD ["serve"]
|