# The binary is NOT compiled here. Build it first, from the repository root: # # (cd web && npm ci && npm run build) # zig build cross -Dweb-dist=web/dist -Doptimize=ReleaseSafe # # then build the image with the repository root as context: # # docker build -t nxdns -f deploy/docker/Dockerfile . # # The builder stage stages the CA bundle (upstream DoH/DoT verification rescans # the system store; a scratch image without one breaks every TLS upstream) and # maps the buildx TARGETARCH onto the zig cross-target directory. The legacy # builder leaves TARGETARCH empty, so the arch falls back to the build host's # `uname -m`: a plain `docker build` must never package a foreign binary that # only fails at `docker run` with exec-format. FROM alpine:3.22 AS builder RUN apk add --no-cache ca-certificates ARG TARGETARCH COPY zig-out/cross /cross RUN mkdir -p /rootfs/etc/ssl/certs /rootfs/etc/nxdns /rootfs/var/lib/nxdns \ && cp /etc/ssl/certs/ca-certificates.crt /rootfs/etc/ssl/certs/ \ && arch="${TARGETARCH:-}" \ && if [ -z "$arch" ]; then case "$(uname -m)" in \ x86_64) arch=amd64 ;; \ aarch64) arch=arm64 ;; \ *) echo "unsupported build host $(uname -m); use buildx" >&2; exit 1 ;; \ esac; fi \ && case "$arch" in \ amd64) cp /cross/x86_64-linux-musl/nxdns /rootfs/nxdns ;; \ arm64) cp /cross/aarch64-linux-musl/nxdns /rootfs/nxdns ;; \ *) echo "unsupported TARGETARCH '${TARGETARCH}'" >&2; exit 1 ;; \ esac \ && chown 65532:65532 /rootfs/var/lib/nxdns FROM scratch COPY --from=builder /rootfs/ / USER 65532:65532 VOLUME /var/lib/nxdns EXPOSE 53/udp 53/tcp 8080 443 853 ENTRYPOINT ["/nxdns"] CMD ["run"]