Skip to content

Commit 429353e

Browse files
committed
build: refactor Dockerfile for multi-stage build and security
- introduce dependencies stage to cache Rust dependencies for faster rebuilds - add maintainer label and configure timezone in runtime stage - install build dependencies and set up Rust toolchain for optimized compilation - strip binary and add security measures like non-root user - clean up apk cache to reduce image size and improve performance Signed-off-by: mingcheng <mingcheng@apache.org>
1 parent ae22edc commit 429353e

1 file changed

Lines changed: 64 additions & 25 deletions

File tree

‎Dockerfile‎

Lines changed: 64 additions & 25 deletions
Original file line numberDiff line numberDiff line change
@@ -1,39 +1,78 @@
1-
FROM rust:alpine AS builder
1+
# Stage 1: Dependencies - Cache Rust dependencies separately for faster rebuilds
2+
FROM rust:alpine AS dependencies
23
LABEL maintainer="mingcheng <mingcheng@apache.org>"
34

4-
# Set the working directory
5-
ENV BUILD_DIR=/build
5+
# Install build dependencies required for compilation
6+
RUN apk add --no-cache \
7+
build-base \
8+
git \
9+
musl-dev \
10+
libressl-dev \
11+
pkgconfig \
12+
perl
13+
14+
# Ensure we're using the latest stable Rust toolchain
15+
RUN rustup default stable && rustup update stable
16+
17+
# Set the working directory for dependency building
18+
WORKDIR /build
19+
20+
# Copy only dependency manifests first to leverage Docker layer caching
21+
COPY Cargo.toml Cargo.lock ./
22+
23+
# Create a dummy source file to build dependencies
24+
RUN mkdir src && \
25+
echo "fn main() {}" > src/main.rs && \
26+
cargo build --release && \
27+
rm -rf src
628

7-
# Add necessary build dependencies
8-
RUN apk add --no-cache build-base git musl-dev libressl-dev pkgconfig perl
29+
# Stage 2: Builder - Build the actual application
30+
FROM dependencies AS builder
931

10-
# Update the latest stable version of rust toolkit
11-
RUN rustup default stable && rustup override set stable
32+
# Copy the actual source code
33+
COPY . .
1234

13-
# Start building the application
14-
COPY . ${BUILD_DIR}
15-
WORKDIR ${BUILD_DIR}
35+
# Build the application with optimizations
36+
RUN cargo build --release && \
37+
strip target/release/aigitcommit && \
38+
cp target/release/aigitcommit /bin/aigitcommit
1639

17-
# Build the application
18-
RUN cargo update \
19-
&& cargo build --release \
20-
&& cp target/release/aigitcommit /bin/aigitcommit
40+
# Stage 3: Runtime - Create minimal runtime image
41+
FROM alpine AS runtime
2142

22-
# Stage2
23-
FROM alpine
43+
# Set timezone (configurable via build args)
44+
ARG TZ=Asia/Shanghai
45+
ENV TZ=${TZ}
2446

25-
# # Install timezone data and set timezone
26-
ENV TZ="Asia/Shanghai"
27-
RUN apk update \
28-
&& apk add --no-cache tzdata git curl \
29-
&& ln -snf /usr/share/zoneinfo/$TZ /etc/localtime \
30-
&& echo $TZ > /etc/timezone
47+
# Install only runtime dependencies
48+
RUN apk add --no-cache \
49+
tzdata \
50+
git \
51+
curl \
52+
ca-certificates && \
53+
ln -snf /usr/share/zoneinfo/$TZ /etc/localtime && \
54+
echo $TZ > /etc/timezone && \
55+
# Clean up apk cache to reduce image size
56+
rm -rf /var/cache/apk/*
3157

32-
# # Copy the binary from the builder stage
58+
# Copy the compiled binary from builder stage
3359
COPY --from=builder /bin/aigitcommit /bin/aigitcommit
3460

35-
# # Set the working directory
61+
# Create a non-root user for security
62+
RUN addgroup -g 1000 aigit && \
63+
adduser -D -u 1000 -G aigit aigit
64+
65+
# Set the working directory
3666
WORKDIR /repo
3767

38-
# # Define the command to run the application
68+
# Change ownership of the working directory
69+
RUN chown -R aigit:aigit /repo
70+
71+
# Switch to non-root user
72+
USER aigit
73+
74+
# Define the entrypoint
3975
ENTRYPOINT ["/bin/aigitcommit"]
76+
77+
# Default command (can be overridden)
78+
CMD ["--help"]

0 commit comments

Comments
 (0)