-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.dynamic
More file actions
70 lines (51 loc) · 1.77 KB
/
Dockerfile.dynamic
File metadata and controls
70 lines (51 loc) · 1.77 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# syntax=docker/dockerfile:1
FROM golangci/golangci-lint:v2.11.4-alpine AS lint
# Build
FROM docker.io/golang:1.26.2-trixie AS build
WORKDIR /app
COPY go.mod ./
COPY go.sum ./
RUN go mod download
COPY epub.go ./epub.go.bak
COPY epub.go ./epub.go
ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
libonig-dev=6.9.9-1+b1 \
libxml2-dev=2.12.7+dfsg+really2.9.14-2.1+deb13u2 \
pkgconf=1.8.1-4 \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*
RUN go fmt && go vet && go fix \
&& diff ./epub.go.bak ./epub.go \
&& go build -trimpath -o epub-LinuxFr.org
RUN go install golang.org/x/vuln/cmd/govulncheck@v1.1.4 \
&& govulncheck -show verbose ./... \
&& govulncheck --mode=binary -show verbose epub-LinuxFr.org
# Lint
COPY --from=lint /usr/bin/golangci-lint "/go/bin/golangci-lint"
RUN golangci-lint run -v
# Deploy
FROM docker.io/debian:trixie
LABEL "org.opencontainers.image.source"="https://github.com/linuxfrorg/epub-LinuxFr.org"
LABEL "org.opencontainers.image.description"="Produce on the fly epub3 from a content on LinuxFr.org and its comments"
LABEL "org.opencontainers.image.licenses"="AGPL-3.0-only"
ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update \
&& apt-get install --assume-yes --no-install-recommends \
adduser=3.152 \
libonig5=6.9.9-1+b1 \
libxml2=2.12.7+dfsg+really2.9.14-2.1+deb13u2 \
ca-certificates=20250419 \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*
ARG UID=1000
ARG GID=1000
RUN addgroup --gid "${GID}" app \
&& adduser --disabled-password --comment '' --home /app --shell /bin/sh --uid "${UID}" --ingroup app app
USER app
WORKDIR /app
COPY --from=build --chown=app:app /app/epub-LinuxFr.org .
EXPOSE 9000
ENTRYPOINT ["/app/epub-LinuxFr.org"]
CMD ["--help"]