176 lines
4.7 KiB
Docker
176 lines
4.7 KiB
Docker
# This file is based on these images:
|
|
#
|
|
# - https://hub.docker.com/r/hexpm/elixir/tags - for the builder image
|
|
# E.g.: docker.io/hexpm/elixir:1.20.2-erlang-29.0.3-debian-trixie-20260713-slim
|
|
# - https://hub.docker.com/_/debian/tags?name=trixie-20260713-slim - for the runner image
|
|
# E.g.: docker.io/debian:trixie-20260713-slim
|
|
#
|
|
# Find builder and runner images on Docker Hub or on Hex's Build Server (Bob).
|
|
# We recommend using Bob's Web UI to find recent tags:
|
|
#
|
|
# - https://bob.hex.pm/docker
|
|
#
|
|
# We suggest using the same Debian version for both the builder and runner images.
|
|
#
|
|
# We suggest Debian/Ubuntu instead of Alpine to avoid production compatibility issues
|
|
# (such as DNS resolution failures, and dynamically linked NIFs/precompiled binaries).
|
|
#
|
|
# For finding packages in Debian, search on https://packages.debian.org/.
|
|
|
|
ARG ELIXIR_VERSION=1.20.2
|
|
ARG OTP_VERSION=29.0.3
|
|
ARG DEBIAN_VERSION=trixie-20260713-slim
|
|
|
|
ARG BUILDER_IMAGE="docker.io/hexpm/elixir:${ELIXIR_VERSION}-erlang-${OTP_VERSION}-debian-${DEBIAN_VERSION}@sha256:6fcd8ea864221b960c1ec418e3b10fa488298ff9e70c9e0f3db18070e610fb8a"
|
|
ARG RUNNER_IMAGE="docker.io/debian:${DEBIAN_VERSION}@sha256:020c0d20b9880058cbe785a9db107156c3c75c2ac944a6aa7ab59f2add76a7bd"
|
|
|
|
FROM docker.io/node:24.18.0-bookworm-slim@sha256:6f7b03f7c2c8e2e784dcf9295400527b9b1270fd37b7e9a7285cf83b6951452d AS node_deps
|
|
|
|
WORKDIR /assets
|
|
COPY assets/package.json assets/package-lock.json ./
|
|
RUN npm install --global npm@12.0.1 \
|
|
&& npm ci
|
|
|
|
FROM ${BUILDER_IMAGE} AS builder
|
|
|
|
# install build dependencies
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
build-essential=12.12 \
|
|
git=1:2.47.3-0+deb13u1 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# prepare build dir
|
|
WORKDIR /app
|
|
|
|
# install hex + rebar
|
|
RUN mix local.hex --force \
|
|
&& mix local.rebar --force
|
|
|
|
# set build ENV
|
|
ENV MIX_ENV="prod"
|
|
|
|
# install mix dependencies
|
|
COPY mix.exs mix.lock ./
|
|
RUN mix deps.get --only $MIX_ENV
|
|
RUN mkdir config
|
|
|
|
ARG WNH_E2E_SSL_EXCLUDE_HOST=
|
|
ENV WNH_E2E_SSL_EXCLUDE_HOST="${WNH_E2E_SSL_EXCLUDE_HOST}"
|
|
|
|
# copy compile-time config files before we compile dependencies
|
|
# to ensure any relevant config change will trigger the dependencies
|
|
# to be re-compiled.
|
|
COPY config/config.exs config/${MIX_ENV}.exs config/
|
|
RUN mix deps.compile
|
|
|
|
RUN mix assets.setup
|
|
|
|
COPY priv priv
|
|
|
|
COPY lib lib
|
|
|
|
# Compile the release
|
|
RUN mix compile
|
|
|
|
COPY assets assets
|
|
COPY --from=node_deps /assets/node_modules assets/node_modules
|
|
|
|
# compile assets
|
|
RUN mix assets.deploy
|
|
|
|
# Changes to config/runtime.exs don't require recompiling the code
|
|
COPY config/runtime.exs config/
|
|
|
|
COPY rel rel
|
|
RUN mix release
|
|
|
|
# start a new build stage so that the final image will only contain
|
|
# the compiled release and other runtime necessities
|
|
FROM ${RUNNER_IMAGE} AS final
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
ca-certificates=20250419 \
|
|
curl=8.14.1-2+deb13u4 \
|
|
libncurses6=6.5+20250216-2 \
|
|
libsctp1=1.0.21+dfsg-1 \
|
|
libstdc++6=14.2.0-19 \
|
|
locales=2.41-12+deb13u3 \
|
|
openssl=3.5.6-1~deb13u2 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Set the locale
|
|
RUN sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen \
|
|
&& locale-gen
|
|
|
|
ENV LANG=en_US.UTF-8
|
|
ENV LANGUAGE=en_US:en
|
|
ENV LC_ALL=en_US.UTF-8
|
|
|
|
WORKDIR "/app"
|
|
RUN chown nobody /app
|
|
|
|
# set runner ENV
|
|
ENV MIX_ENV="prod"
|
|
|
|
# Only copy the final release from the build stage
|
|
COPY --from=builder --chown=nobody:root /app/_build/${MIX_ENV}/rel/who_need_help ./
|
|
|
|
USER nobody
|
|
|
|
# If using an environment that doesn't automatically reap zombie processes, it is
|
|
# advised to add an init process such as tini via `apt-get install`
|
|
# above and adding an entrypoint. See https://github.com/krallin/tini for details
|
|
# ENTRYPOINT ["/tini", "--"]
|
|
|
|
CMD ["/app/bin/server"]
|
|
|
|
FROM ${BUILDER_IMAGE} AS test
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
build-essential=12.12 \
|
|
ca-certificates=20250419 \
|
|
git=1:2.47.3-0+deb13u1 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
RUN mix local.hex --force \
|
|
&& mix local.rebar --force
|
|
|
|
ENV MIX_ENV="test"
|
|
|
|
COPY mix.exs mix.lock ./
|
|
RUN mix deps.get --only test
|
|
|
|
COPY config config
|
|
RUN mix deps.compile
|
|
|
|
COPY .dialyzer_ignore.exs .formatter.exs ./
|
|
COPY priv priv
|
|
COPY lib lib
|
|
COPY test test
|
|
|
|
RUN mix compile
|
|
|
|
CMD ["mix", "test"]
|
|
|
|
FROM test AS quality
|
|
|
|
# PLTs are expensive to create but deterministic for the pinned Erlang,
|
|
# Elixir, dependency lock, and test environment. Cache them in this dedicated
|
|
# target so every quality command uses the same analyzed dependency set.
|
|
RUN mix dialyzer --plt
|
|
|
|
CMD ["mix", "dialyzer"]
|
|
|
|
FROM builder AS load_tools
|
|
|
|
CMD ["mix", "wnh.load_fixtures"]
|
|
|
|
# Keep the production release as the default build result while exposing the
|
|
# dedicated `test`, `quality`, and isolated `load_tools` targets to local
|
|
# verification scripts.
|
|
FROM final AS release
|