- golang.org/x/text v0.37.0 -> v0.39.0 (GO-2026-5970, infinite loop on invalid input, reachable from pgxpool). x/sync follows to v0.21.0. - web lockfile: in-range updates from `npm audit fix` for devalue (high) and svelte (moderate), both of which ship in the browser bundle. package.json is unchanged. - Dockerfile builder golang:1.25 -> golang:1.26. CI has tested on 1.26 since the ci-go migration while the image was still compiled with 1.25, left over from the April skeleton; the shipped binary now uses the toolchain the tests ran on. govulncheck under golang:1.26-bookworm (go1.26.8) reports 0 vulnerabilities reachable from our code. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
71 lines
3.0 KiB
Docker
71 lines
3.0 KiB
Docker
# syntax=docker/dockerfile:1.6
|
|
|
|
FROM node:22-bookworm-slim AS web
|
|
WORKDIR /web
|
|
COPY web/package.json web/package-lock.json ./
|
|
RUN npm ci
|
|
COPY web/ ./
|
|
RUN npm run build
|
|
|
|
FROM golang:1.26-bookworm AS builder
|
|
WORKDIR /src
|
|
COPY go.mod go.sum ./
|
|
RUN go mod download
|
|
COPY . .
|
|
# Overwrite the committed placeholder with the freshly-built SPA assets.
|
|
COPY --from=web /web/build ./web/build
|
|
ENV CGO_ENABLED=0
|
|
# Version stamping. release.yml passes the DERIVED version name
|
|
# (YYYY.MM.DD.HHMM) and the lane's channel; a local `docker build` falls back
|
|
# to "dev"/"local". Both are surfaced at /healthz.
|
|
#
|
|
# These are two values on purpose (family rule 149): the same commit built on
|
|
# dev and on main reports the same NAME and differs only in CHANNEL. Folding
|
|
# the channel into the version string is what the rule forbids — the version
|
|
# used to BE the channel word here ("main"/"dev"), which meant two dev images
|
|
# eight weeks apart were indistinguishable.
|
|
ARG MINSTREL_VERSION=dev
|
|
ARG MINSTREL_CHANNEL=local
|
|
RUN go build -trimpath \
|
|
-ldflags="-s -w \
|
|
-X 'git.fabledsword.com/bvandeusen/minstrel/internal/server.ServerVersion=${MINSTREL_VERSION}' \
|
|
-X 'git.fabledsword.com/bvandeusen/minstrel/internal/server.ServerChannel=${MINSTREL_CHANNEL}'" \
|
|
-o /out/minstrel ./cmd/minstrel
|
|
|
|
FROM debian:bookworm-slim
|
|
# ffmpeg: duration probes and the exact-tier audio hash (a SHA-256 of the
|
|
# encoded audio packets, so no decode). libchromaprint-tools: fpcalc, the
|
|
# acoustic fingerprint that tells the same recording at two bitrates apart
|
|
# from two different recordings (M400). Both are baked in at build time so a
|
|
# deployed instance never fetches either (rule 164); fpcalc is shelled out
|
|
# rather than bound because CGO_ENABLED=0 above rules out cgo.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends ca-certificates ffmpeg libchromaprint-tools \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN groupadd --system --gid 1000 minstrel \
|
|
&& useradd --system --uid 1000 --gid minstrel --shell /usr/sbin/nologin minstrel
|
|
|
|
COPY --from=builder /out/minstrel /usr/local/bin/minstrel
|
|
COPY config.example.yaml /etc/smartmusic/config.yaml
|
|
|
|
# Pre-create the data directory owned by the runtime user. Cached artifacts
|
|
# (playlist cover collages, artist art, album-cover fallbacks) all land here.
|
|
# A non-writable path at this location silently breaks every downstream
|
|
# cache, so we create + chown it once at image build. Operators mount a
|
|
# named volume on top to persist across container recreates.
|
|
RUN mkdir -p /app/data /app/client && chown -R minstrel:minstrel /app
|
|
WORKDIR /app
|
|
|
|
# In-app update channel (#397). client/ in the build context holds
|
|
# minstrel.apk + minstrel.apk.version (populated by release.yml on tag
|
|
# pushes; .gitkeep + README otherwise). Endpoints return 404 when the
|
|
# APK files aren't present, so non-tag images degrade gracefully.
|
|
COPY --chown=minstrel:minstrel client/ /app/client/
|
|
|
|
USER minstrel
|
|
EXPOSE 4533
|
|
ENV MINSTREL_STORAGE_DATA_DIR=/app/data
|
|
ENTRYPOINT ["/usr/local/bin/minstrel"]
|
|
CMD ["--config", "/etc/smartmusic/config.yaml"]
|