# syntax=docker/dockerfile:1.6 FROM node:22-bookworm-slim AS web WORKDIR /web COPY web/package.json web/package-lock.json ./ RUN npm ci COPY web/ ./ RUN npm run build FROM golang:1.25-bookworm AS builder WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . # Overwrite the committed placeholder with the freshly-built SPA assets. COPY --from=web /web/build ./web/build ENV CGO_ENABLED=0 # Version stamping. release.yml passes the DERIVED version name # (YYYY.MM.DD.HHMM) and the lane's channel; a local `docker build` falls back # to "dev"/"local". Both are surfaced at /healthz. # # These are two values on purpose (family rule 149): the same commit built on # dev and on main reports the same NAME and differs only in CHANNEL. Folding # the channel into the version string is what the rule forbids — the version # used to BE the channel word here ("main"/"dev"), which meant two dev images # eight weeks apart were indistinguishable. ARG MINSTREL_VERSION=dev ARG MINSTREL_CHANNEL=local RUN go build -trimpath \ -ldflags="-s -w \ -X 'git.fabledsword.com/bvandeusen/minstrel/internal/server.ServerVersion=${MINSTREL_VERSION}' \ -X 'git.fabledsword.com/bvandeusen/minstrel/internal/server.ServerChannel=${MINSTREL_CHANNEL}'" \ -o /out/minstrel ./cmd/minstrel FROM debian:bookworm-slim RUN apt-get update \ && apt-get install -y --no-install-recommends ca-certificates ffmpeg \ && rm -rf /var/lib/apt/lists/* RUN groupadd --system --gid 1000 minstrel \ && useradd --system --uid 1000 --gid minstrel --shell /usr/sbin/nologin minstrel COPY --from=builder /out/minstrel /usr/local/bin/minstrel COPY config.example.yaml /etc/smartmusic/config.yaml # Pre-create the data directory owned by the runtime user. Cached artifacts # (playlist cover collages, artist art, album-cover fallbacks) all land here. # A non-writable path at this location silently breaks every downstream # cache, so we create + chown it once at image build. Operators mount a # named volume on top to persist across container recreates. RUN mkdir -p /app/data /app/client && chown -R minstrel:minstrel /app WORKDIR /app # In-app update channel (#397). client/ in the build context holds # minstrel.apk + minstrel.apk.version (populated by release.yml on tag # pushes; .gitkeep + README otherwise). Endpoints return 404 when the # APK files aren't present, so non-tag images degrade gracefully. COPY --chown=minstrel:minstrel client/ /app/client/ USER minstrel EXPOSE 4533 ENV MINSTREL_STORAGE_DATA_DIR=/app/data ENTRYPOINT ["/usr/local/bin/minstrel"] CMD ["--config", "/etc/smartmusic/config.yaml"]