Dockerfile.build 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142
  1. # syntax=docker/dockerfile:1.4
  2. # smartbotic-automation Package Builder
  3. # Compiles the C++ binaries + WebUI bundle, then assembles a single .deb.
  4. #
  5. # Build:
  6. # docker buildx build -f packaging/Dockerfile.build \
  7. # --build-arg BASE_IMAGE=smartbotic-automation-build-base:debian13 \
  8. # --build-arg BUILD_VERSION=1.0.0 \
  9. # --target packages \
  10. # --output "type=local,dest=dist/debian13/" .
  11. ARG BASE_IMAGE=debian:trixie
  12. FROM ${BASE_IMAGE} AS builder
  13. ARG BUILD_VERSION=0.0.0
  14. ARG BUILD_DEB_REVISION=1
  15. ARG BUILD_JOBS=8
  16. ARG BUILD_GIT_COMMIT=unknown
  17. ENV DEBIAN_FRONTEND=noninteractive
  18. ENV BUILD_VERSION=${BUILD_VERSION}
  19. ENV BUILD_DEB_REVISION=${BUILD_DEB_REVISION}
  20. ENV BUILD_JOBS=${BUILD_JOBS}
  21. ENV CCACHE_DIR=/ccache
  22. ENV CCACHE_MAXSIZE=5G
  23. ENV PATH="/usr/lib/ccache:${PATH}"
  24. # Fall back to fresh dep install if the base image isn't our prebuilt one
  25. RUN if [ ! -f /etc/smartbotic-automation-build-base ]; then \
  26. apt-get update && apt-get install -y --no-install-recommends \
  27. build-essential cmake ninja-build git pkg-config ccache dpkg-dev \
  28. libssl-dev zlib1g-dev libbrotli-dev uuid-dev \
  29. protobuf-compiler libprotobuf-dev libgrpc++-dev protobuf-compiler-grpc \
  30. nlohmann-json3-dev libspdlog-dev libfmt-dev libcurl4-openssl-dev libwebsockets-dev \
  31. libmariadb-dev libpq-dev \
  32. nodejs npm libsmartbotic-db-client-dev \
  33. && rm -rf /var/lib/apt/lists/*; \
  34. else echo "Using pre-built base: $(cat /etc/smartbotic-automation-build-base)"; fi
  35. WORKDIR /build
  36. # WebUI build (cached separately from C++)
  37. COPY webui/package.json webui/package-lock.json ./webui/
  38. RUN --mount=type=cache,target=/npm-cache,id=smartbotic-automation-npm-cache \
  39. cd webui && npm ci --cache /npm-cache
  40. COPY VERSION ./
  41. COPY webui/ ./webui/
  42. RUN cd webui && npm run build
  43. # C++ build
  44. COPY CMakeLists.txt ./
  45. COPY cmake/ ./cmake/
  46. COPY proto/ ./proto/
  47. COPY lib/ ./lib/
  48. COPY src/ ./src/
  49. COPY config/ ./config/
  50. COPY nodes/ ./nodes/
  51. COPY packaging/ ./packaging/
  52. RUN --mount=type=cache,target=/ccache,id=smartbotic-automation-ccache \
  53. cmake -B build -G Ninja \
  54. -DCMAKE_BUILD_TYPE=Release \
  55. -DCMAKE_C_COMPILER_LAUNCHER=ccache \
  56. -DCMAKE_CXX_COMPILER_LAUNCHER=ccache \
  57. && cmake --build build --parallel ${BUILD_JOBS} \
  58. && (ccache --show-stats || true)
  59. # ----- Package assembly stage -----
  60. FROM builder AS packager
  61. RUN mkdir -p /packages
  62. RUN chmod +x /build/packaging/scripts/create-deb.sh \
  63. && OUTPUT_DIR=/packages /build/packaging/scripts/create-deb.sh
  64. # ----- Final export stage -----
  65. FROM scratch AS packages
  66. COPY --from=packager /packages/*.deb /
  67. # ----- Runtime image -----
  68. # A slim image that runs the services, as opposed to the `packages` stage which
  69. # only emits a .deb. Built by hand rather than by installing that .deb, because
  70. # the package pulls in a chain intended for a single-machine install; here the
  71. # database is a separate container and each service must be free to run on its
  72. # own host.
  73. #
  74. # docker buildx build -f packaging/Dockerfile.build \
  75. # --build-arg BASE_IMAGE=smartbotic-automation-build-base:debian13 \
  76. # --build-arg REPO_PASS=<password> \
  77. # --target runtime -t smartbotic-automation:current .
  78. FROM debian:trixie-slim AS runtime
  79. ENV DEBIAN_FRONTEND=noninteractive
  80. ARG REPO_USER=callerai
  81. ARG REPO_PASS
  82. COPY packaging/smartbotics-repo.gpg /usr/share/keyrings/smartbotics-repo.gpg
  83. # libsmartbotic-db-client comes from the SmartBotics repo; everything else is
  84. # Debian. The credential is written and removed inside one layer so it is not
  85. # left in the image.
  86. RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates \
  87. && echo "deb [signed-by=/usr/share/keyrings/smartbotics-repo.gpg] https://repository.smartbotics.ai trixie main" \
  88. > /etc/apt/sources.list.d/smartbotics.list \
  89. && printf "machine repository.smartbotics.ai\nlogin %s\npassword %s\n" \
  90. "$REPO_USER" "$REPO_PASS" > /etc/apt/auth.conf.d/smartbotics.conf \
  91. && chmod 600 /etc/apt/auth.conf.d/smartbotics.conf \
  92. && apt-get update \
  93. && apt-get install -y --no-install-recommends \
  94. libsmartbotic-db-client \
  95. libssl3t64 libprotobuf32t64 libgrpc++1.51t64 libspdlog1.15 libfmt10 \
  96. libuuid1 libcurl4t64 zlib1g libbrotli1 libwebsockets19t64 \
  97. libmariadb3 libpq5 \
  98. tzdata \
  99. && rm -f /etc/apt/auth.conf.d/smartbotics.conf /etc/apt/sources.list.d/smartbotics.list \
  100. && rm -rf /var/lib/apt/lists/*
  101. # Timezone data matters here: cron schedules are evaluated in the workflow's own
  102. # zone through std::chrono::locate_zone, which needs the IANA database present.
  103. # Without tzdata every zone falls back to UTC and a workflow set for 02:00
  104. # Europe/Budapest fires at the wrong hour, silently.
  105. RUN useradd --system --create-home --home-dir /var/lib/smartbotic --shell /usr/sbin/nologin smartbotic
  106. COPY --from=builder /build/build/smartbotic-webserver /usr/bin/
  107. COPY --from=builder /build/build/smartbotic-runner /usr/bin/
  108. COPY --from=builder /build/webui/dist/ /usr/share/smartbotic-automation/webui/
  109. COPY --from=builder /build/nodes/ /usr/share/smartbotic-automation/nodes/
  110. COPY --from=builder /build/config/ /usr/share/smartbotic-automation/config/
  111. # The working directory is what config/ and data/ resolve against.
  112. WORKDIR /var/lib/smartbotic
  113. RUN mkdir -p /var/lib/smartbotic/data /var/lib/smartbotic/config \
  114. && cp -r /usr/share/smartbotic-automation/config/. /var/lib/smartbotic/config/ \
  115. && ln -s /usr/share/smartbotic-automation/nodes /var/lib/smartbotic/nodes \
  116. && chown -R smartbotic:smartbotic /var/lib/smartbotic
  117. USER smartbotic
  118. ENV WEBUI_PATH=/usr/share/smartbotic-automation/webui \
  119. NODES_PATH=/usr/share/smartbotic-automation/nodes \
  120. LOG_LEVEL=info
  121. # No default CMD: compose names the service to run, because one image serves
  122. # both and guessing here would start the wrong one.