mirror of
https://github.com/suitenumerique/messages.git
synced 2026-09-28 12:45:00 +02:00
* (ops) implement production docker images
Github workflows:
- moved docker-publish jobs into a separate file on push main only
Backend:
- added healthcheck on backend Dockerfile + minor fixes
- bumped django to 5.1.15 to mitigate major CVE
- moved /healthz endpoint to /__heartbeat__ + added db connection
check
Frontend:
- Added runtime-prod Dockerfile target + minor fixes on the Dockerfile
- bump next to 15.5.9 to mitigate major CVE
- moved nginx config to standard nginx container configuration
template, fixed `scalingo_postfrontend` accordingly
Keycloak:
- Added production Dockerfile
- Removed scalingo_pgdump script & cron.json
socks-proxy:
- added package upgrades run into runtime Dockerfile stage
Misc:
- removed scalingo_pgdump.sh & cron.json
- fixed compose and e2e nginx configs with /healthz replacement
* (fix) coderabbit recommandations
39 lines
1001 B
Docker
39 lines
1001 B
Docker
FROM debian:trixie-slim AS base
|
|
|
|
ARG DANTE_VER=1.4.4
|
|
ARG DANTE_URL=https://www.inet.no/dante/files/dante-$DANTE_VER.tar.gz
|
|
ARG DANTE_SHA256=1973c7732f1f9f0a4c0ccf2c1ce462c7c25060b25643ea90f9b98f53a813faec
|
|
|
|
RUN <<EOR
|
|
apt-get update
|
|
DEBIAN_FRONTEND="noninteractive" apt-get install -y build-essential curl
|
|
rm -rf /var/lib/apt/lists/*
|
|
EOR
|
|
|
|
RUN <<EOR
|
|
set -eu
|
|
curl -fsSL -o dante.tar.gz $DANTE_URL
|
|
echo "$DANTE_SHA256 dante.tar.gz" | sha256sum -c -
|
|
tar -xzf dante.tar.gz
|
|
cd dante-$DANTE_VER
|
|
./configure
|
|
make
|
|
make install
|
|
EOR
|
|
|
|
FROM debian:trixie-slim AS runtime
|
|
|
|
RUN <<EOR
|
|
apt-get update
|
|
DEBIAN_FRONTEND="noninteractive" apt-get upgrade -y
|
|
rm -rf /var/lib/apt/lists/*
|
|
EOR
|
|
|
|
COPY --from=base /usr/local/sbin/sockd /usr/local/sbin/sockd
|
|
COPY --chmod=0755 entrypoint.sh /entrypoint.sh
|
|
|
|
ENTRYPOINT ["/entrypoint.sh"]
|
|
HEALTHCHECK --interval=30s --timeout=3s --start-interval=5s \
|
|
CMD cat /proc/$(cat /var/run/sockd.pid)/status | grep State | grep -E 'R \(running\)|S \(sleeping\)'
|
|
CMD ["/usr/local/sbin/sockd"]
|