1
Fork 0
blog-zig-mongo/Dockerfile
Leonardo Devai 1f6fe54fa2 Review and modernize all 42 projects to the updated standard
Pinned 2026 toolchains (Go 1.26, Rust 1.98/edition 2024, Python 3.14 + uv, Node 24,
Zig 0.16, NixOS 26.05), postgres 18 / mongo 8, lockfiles built from, non-root
runtimes, .dockerignore, per-project LICENSE, READMEs with the git.devai.io clone
line, checkout@v7 CI. Security fixes in the legacy Rust APIs (any-password login,
self-assigned admin, hard-coded JWT secret), JWT alg/exp/sub enforcement across the
blog series, safe markdown links in the frontends, and many smaller bugs — every
project was built, run and exercised end to end.

Adds scripts/publish.sh + a CI publish job that splits every folder into its own
repo at git.devai.io/templates/<folder>.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01128fhuZbgivaSJvtMf4s1G
2026-09-27 21:10:38 +02:00

23 lines
891 B
Docker

FROM debian:trixie-slim AS build
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates curl xz-utils libmongoc-dev pkg-config \
&& rm -rf /var/lib/apt/lists/*
ARG ZIG_VERSION=0.16.0
RUN curl -fsSL "https://ziglang.org/download/${ZIG_VERSION}/zig-$(uname -m)-linux-${ZIG_VERSION}.tar.xz" \
| tar -xJ -C /opt \
&& ln -s "/opt/zig-$(uname -m)-linux-${ZIG_VERSION}/zig" /usr/local/bin/zig
WORKDIR /app
COPY build.zig build.zig.zon ./
COPY src ./src
# -Dcpu=baseline: run on any CPU of this architecture, not just the build machine's.
RUN zig build -Doptimize=ReleaseSafe -Dcpu=baseline
FROM debian:trixie-slim
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates libmongoc-1.0-0t64 \
&& rm -rf /var/lib/apt/lists/*
COPY --from=build /app/zig-out/bin/blog /usr/local/bin/blog
USER nobody
ENV PORT=8080
EXPOSE 8080
CMD ["blog"]