|
@@ -32,6 +32,7 @@ RUN if [ ! -f /etc/smartbotic-automation-build-base ]; then \
|
|
|
libssl-dev zlib1g-dev libbrotli-dev uuid-dev \
|
|
libssl-dev zlib1g-dev libbrotli-dev uuid-dev \
|
|
|
protobuf-compiler libprotobuf-dev libgrpc++-dev protobuf-compiler-grpc \
|
|
protobuf-compiler libprotobuf-dev libgrpc++-dev protobuf-compiler-grpc \
|
|
|
nlohmann-json3-dev libspdlog-dev libfmt-dev libcurl4-openssl-dev libwebsockets-dev \
|
|
nlohmann-json3-dev libspdlog-dev libfmt-dev libcurl4-openssl-dev libwebsockets-dev \
|
|
|
|
|
+ libmariadb-dev libpq-dev \
|
|
|
nodejs npm libsmartbotic-db-client-dev \
|
|
nodejs npm libsmartbotic-db-client-dev \
|
|
|
&& rm -rf /var/lib/apt/lists/*; \
|
|
&& rm -rf /var/lib/apt/lists/*; \
|
|
|
else echo "Using pre-built base: $(cat /etc/smartbotic-automation-build-base)"; fi
|
|
else echo "Using pre-built base: $(cat /etc/smartbotic-automation-build-base)"; fi
|
|
@@ -73,3 +74,69 @@ RUN chmod +x /build/packaging/scripts/create-deb.sh \
|
|
|
# ----- Final export stage -----
|
|
# ----- Final export stage -----
|
|
|
FROM scratch AS packages
|
|
FROM scratch AS packages
|
|
|
COPY --from=packager /packages/*.deb /
|
|
COPY --from=packager /packages/*.deb /
|
|
|
|
|
+
|
|
|
|
|
+# ----- Runtime image -----
|
|
|
|
|
+# A slim image that runs the services, as opposed to the `packages` stage which
|
|
|
|
|
+# only emits a .deb. Built by hand rather than by installing that .deb, because
|
|
|
|
|
+# the package pulls in a chain intended for a single-machine install; here the
|
|
|
|
|
+# database is a separate container and each service must be free to run on its
|
|
|
|
|
+# own host.
|
|
|
|
|
+#
|
|
|
|
|
+# docker buildx build -f packaging/Dockerfile.build \
|
|
|
|
|
+# --build-arg BASE_IMAGE=smartbotic-automation-build-base:debian13 \
|
|
|
|
|
+# --build-arg REPO_PASS=<password> \
|
|
|
|
|
+# --target runtime -t smartbotic-automation:current .
|
|
|
|
|
+FROM debian:trixie-slim AS runtime
|
|
|
|
|
+
|
|
|
|
|
+ENV DEBIAN_FRONTEND=noninteractive
|
|
|
|
|
+
|
|
|
|
|
+ARG REPO_USER=callerai
|
|
|
|
|
+ARG REPO_PASS
|
|
|
|
|
+COPY packaging/smartbotics-repo.gpg /usr/share/keyrings/smartbotics-repo.gpg
|
|
|
|
|
+
|
|
|
|
|
+# libsmartbotic-db-client comes from the SmartBotics repo; everything else is
|
|
|
|
|
+# Debian. The credential is written and removed inside one layer so it is not
|
|
|
|
|
+# left in the image.
|
|
|
|
|
+RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates \
|
|
|
|
|
+ && echo "deb [signed-by=/usr/share/keyrings/smartbotics-repo.gpg] https://repository.smartbotics.ai trixie main" \
|
|
|
|
|
+ > /etc/apt/sources.list.d/smartbotics.list \
|
|
|
|
|
+ && printf "machine repository.smartbotics.ai\nlogin %s\npassword %s\n" \
|
|
|
|
|
+ "$REPO_USER" "$REPO_PASS" > /etc/apt/auth.conf.d/smartbotics.conf \
|
|
|
|
|
+ && chmod 600 /etc/apt/auth.conf.d/smartbotics.conf \
|
|
|
|
|
+ && apt-get update \
|
|
|
|
|
+ && apt-get install -y --no-install-recommends \
|
|
|
|
|
+ libsmartbotic-db-client \
|
|
|
|
|
+ libssl3t64 libprotobuf32t64 libgrpc++1.51t64 libspdlog1.15 libfmt10 \
|
|
|
|
|
+ libuuid1 libcurl4t64 zlib1g libbrotli1 libwebsockets19t64 \
|
|
|
|
|
+ libmariadb3 libpq5 \
|
|
|
|
|
+ tzdata \
|
|
|
|
|
+ && rm -f /etc/apt/auth.conf.d/smartbotics.conf /etc/apt/sources.list.d/smartbotics.list \
|
|
|
|
|
+ && rm -rf /var/lib/apt/lists/*
|
|
|
|
|
+
|
|
|
|
|
+# Timezone data matters here: cron schedules are evaluated in the workflow's own
|
|
|
|
|
+# zone through std::chrono::locate_zone, which needs the IANA database present.
|
|
|
|
|
+# Without tzdata every zone falls back to UTC and a workflow set for 02:00
|
|
|
|
|
+# Europe/Budapest fires at the wrong hour, silently.
|
|
|
|
|
+
|
|
|
|
|
+RUN useradd --system --create-home --home-dir /var/lib/smartbotic --shell /usr/sbin/nologin smartbotic
|
|
|
|
|
+
|
|
|
|
|
+COPY --from=builder /build/build/smartbotic-webserver /usr/bin/
|
|
|
|
|
+COPY --from=builder /build/build/smartbotic-runner /usr/bin/
|
|
|
|
|
+COPY --from=builder /build/webui/dist/ /usr/share/smartbotic-automation/webui/
|
|
|
|
|
+COPY --from=builder /build/nodes/ /usr/share/smartbotic-automation/nodes/
|
|
|
|
|
+COPY --from=builder /build/config/ /usr/share/smartbotic-automation/config/
|
|
|
|
|
+
|
|
|
|
|
+# The working directory is what config/ and data/ resolve against.
|
|
|
|
|
+WORKDIR /var/lib/smartbotic
|
|
|
|
|
+RUN mkdir -p /var/lib/smartbotic/data /var/lib/smartbotic/config \
|
|
|
|
|
+ && cp -r /usr/share/smartbotic-automation/config/. /var/lib/smartbotic/config/ \
|
|
|
|
|
+ && ln -s /usr/share/smartbotic-automation/nodes /var/lib/smartbotic/nodes \
|
|
|
|
|
+ && chown -R smartbotic:smartbotic /var/lib/smartbotic
|
|
|
|
|
+
|
|
|
|
|
+USER smartbotic
|
|
|
|
|
+ENV WEBUI_PATH=/usr/share/smartbotic-automation/webui \
|
|
|
|
|
+ NODES_PATH=/usr/share/smartbotic-automation/nodes \
|
|
|
|
|
+ LOG_LEVEL=info
|
|
|
|
|
+
|
|
|
|
|
+# No default CMD: compose names the service to run, because one image serves
|
|
|
|
|
+# both and guessing here would start the wrong one.
|