43 lines
1.7 KiB
Docker
43 lines
1.7 KiB
Docker
# The binary is NOT compiled here. Build it first, from the repository root:
|
|
#
|
|
# (cd web && npm ci && npm run build)
|
|
# zig build cross -Dweb-dist=web/dist -Doptimize=ReleaseSafe
|
|
#
|
|
# then build the image with the repository root as context:
|
|
#
|
|
# docker build -t nxdns -f deploy/docker/Dockerfile .
|
|
#
|
|
# The builder stage stages the CA bundle (upstream DoH/DoT verification rescans
|
|
# the system store; a scratch image without one breaks every TLS upstream) and
|
|
# maps the buildx TARGETARCH onto the zig cross-target directory. The legacy
|
|
# builder leaves TARGETARCH empty, so the arch falls back to the build host's
|
|
# `uname -m`: a plain `docker build` must never package a foreign binary that
|
|
# only fails at `docker run` with exec-format.
|
|
|
|
FROM alpine:3.22 AS builder
|
|
RUN apk add --no-cache ca-certificates
|
|
ARG TARGETARCH
|
|
COPY zig-out/cross /cross
|
|
RUN mkdir -p /rootfs/etc/ssl/certs /rootfs/etc/nxdns /rootfs/var/lib/nxdns \
|
|
&& cp /etc/ssl/certs/ca-certificates.crt /rootfs/etc/ssl/certs/ \
|
|
&& arch="${TARGETARCH:-}" \
|
|
&& if [ -z "$arch" ]; then case "$(uname -m)" in \
|
|
x86_64) arch=amd64 ;; \
|
|
aarch64) arch=arm64 ;; \
|
|
*) echo "unsupported build host $(uname -m); use buildx" >&2; exit 1 ;; \
|
|
esac; fi \
|
|
&& case "$arch" in \
|
|
amd64) cp /cross/x86_64-linux-musl/nxdns /rootfs/nxdns ;; \
|
|
arm64) cp /cross/aarch64-linux-musl/nxdns /rootfs/nxdns ;; \
|
|
*) echo "unsupported TARGETARCH '${TARGETARCH}'" >&2; exit 1 ;; \
|
|
esac \
|
|
&& chown 65532:65532 /rootfs/var/lib/nxdns
|
|
|
|
FROM scratch
|
|
COPY --from=builder /rootfs/ /
|
|
USER 65532:65532
|
|
VOLUME /var/lib/nxdns
|
|
EXPOSE 53/udp 53/tcp 8080 443 853
|
|
ENTRYPOINT ["/nxdns"]
|
|
CMD ["run"]
|