1
Fork 0
rust-docker-pipeline/Dockerfile
Leonardo Devai 3d649eede9 Review and modernize all 42 projects to the updated standard
Pinned 2026 toolchains (Go 1.26, Rust 1.98/edition 2024, Python 3.14 + uv, Node 24,
Zig 0.16, NixOS 26.05), postgres 18 / mongo 8, lockfiles built from, non-root
runtimes, .dockerignore, per-project LICENSE, READMEs with the git.devai.io clone
line, checkout@v7 CI. Security fixes in the legacy Rust APIs (any-password login,
self-assigned admin, hard-coded JWT secret), JWT alg/exp/sub enforcement across the
blog series, safe markdown links in the frontends, and many smaller bugs — every
project was built, run and exercised end to end.

Adds scripts/publish.sh + a CI publish job that splits every folder into its own
repo at git.devai.io/templates/<folder>.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01128fhuZbgivaSJvtMf4s1G
2026-09-27 21:10:38 +02:00

32 lines
1.3 KiB
Docker

# cargo-chef splits the build in two: your dependencies (slow to compile, rarely
# change) and your code (quick, changes all the time). Docker caches the first.
FROM rust:1.98-slim-trixie AS chef
RUN cargo install cargo-chef --version 0.1.78 --locked
WORKDIR /app
# 1. Plan: boil the project down to recipe.json (manifests + lockfile, no code).
FROM chef AS planner
COPY Cargo.toml Cargo.lock ./
COPY src ./src
RUN cargo chef prepare --recipe-path recipe.json
# 2. Cook: compile only the dependencies. This layer is reused as long as
# recipe.json is unchanged, i.e. until Cargo.toml or Cargo.lock change.
FROM chef AS builder
COPY --from=planner /app/recipe.json recipe.json
RUN cargo chef cook --release --locked --recipe-path recipe.json
# 3. Build: compile your code on top of the cached dependencies.
COPY Cargo.toml Cargo.lock ./
COPY src ./src
RUN cargo build --release --locked
# `docker build --target export --output bin .` writes the binary to ./bin.
FROM scratch AS export
COPY --from=builder /app/target/release/rust-docker-pipeline /
# Run: the binary alone on a minimal, non-root base image.
FROM gcr.io/distroless/cc-debian13:nonroot
COPY --from=builder /app/target/release/rust-docker-pipeline /usr/local/bin/app
EXPOSE 8080
ENTRYPOINT ["/usr/local/bin/app"]