120 lines
4.7 KiB
Docker
120 lines
4.7 KiB
Docker
ARG DEBIAN_TAG=stable
|
|
ARG DEBIAN_VERSION=MUST_PROVIDE_DEBIAN_VERSION
|
|
FROM debian:${DEBIAN_TAG} AS base
|
|
|
|
# Re-declare ARG after FROM
|
|
ARG DEBIAN_TAG
|
|
ARG DEBIAN_VERSION=MUST_PROVIDE_DEBIAN_VERSION
|
|
ARG TARGETARCH
|
|
|
|
# Set shell options for better error detection
|
|
#SHELL ["/bin/bash", "-e", "-c"]
|
|
|
|
# Force non-interactive apt and disable Python bytecode compilation (QEMU workaround)
|
|
ENV DEBIAN_FRONTEND=noninteractive \
|
|
PYTHONDONTWRITEBYTECODE=1
|
|
|
|
# Metadata (will be updated with actual versions during build)
|
|
LABEL org.opencontainers.image.title="orinoco-runner-debian${DEBIAN_VERSION}" \
|
|
org.opencontainers.image.description="Runner image for forgejo-aneksajo built on Debian ${DEBIAN_VERSION}" \
|
|
org.opencontainers.image.url="https://hub.datalad.org/forgejo/runner-images" \
|
|
org.opencontainers.image.source="https://hub.datalad.org/forgejo/runner-images" \
|
|
org.opencontainers.image.documentation="https://hub.datalad.org/forgejo/runner-images/src/branch/main/README.md" \
|
|
org.opencontainers.image.vendor="hub.datalad.org" \
|
|
org.opencontainers.image.licenses="MIT" \
|
|
org.opencontainers.image.authors="Michael Hanke"
|
|
|
|
# Layer: Core build tools (rarely change - every few months)
|
|
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked,id=act-debian-apt-cache-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
--mount=type=cache,target=/var/lib/apt/lists,sharing=locked,id=act-debian-apt-lists-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
# Configure APT for containerised builds \
|
|
rm -f /etc/apt/apt.conf.d/docker-clean && \
|
|
echo 'APT::Sandbox::User "root";' > /etc/apt/apt.conf.d/00docker-buildkit && \
|
|
echo 'Dpkg::Use-Pty "0";' >> /etc/apt/apt.conf.d/00docker-buildkit && \
|
|
apt-get -qq update && apt-get -qq install -y --no-install-recommends \
|
|
# Build tools and compression utilities (alphabetically sorted)
|
|
apt-utils \
|
|
build-essential \
|
|
curl \
|
|
file \
|
|
gzip \
|
|
jq \
|
|
libffi-dev \
|
|
rsync \
|
|
sudo \
|
|
unzip \
|
|
wget \
|
|
zip \
|
|
&& apt-get clean
|
|
|
|
# Layer: System essentials with Python (required for package management)
|
|
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked,id=act-debian-apt-cache-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
--mount=type=cache,target=/var/lib/apt/lists,sharing=locked,id=act-debian-apt-lists-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
apt-get -qq update && apt-get -qq install -y --no-install-recommends \
|
|
ca-certificates \
|
|
git \
|
|
gnupg \
|
|
gpg \
|
|
libcairo2 \
|
|
libssl-dev \
|
|
lsb-release \
|
|
openssh-client \
|
|
python3 \
|
|
python3-apt \
|
|
python3-setuptools \
|
|
python3-venv \
|
|
&& apt-get clean \
|
|
&& update-alternatives --install /usr/bin/python python /usr/bin/python3 100
|
|
|
|
# Layer: Docker installation
|
|
# Using docker.io package for consistent multi-architecture support
|
|
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked,id=act-debian-apt-cache-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
--mount=type=cache,target=/var/lib/apt/lists,sharing=locked,id=act-debian-apt-lists-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
apt-get -qq update && apt-get -qq install -y --no-install-recommends \
|
|
docker-compose \
|
|
docker.io \
|
|
docker-cli \
|
|
&& apt-get clean \
|
|
&& mkdir -p -m 755 /opt/hostedtoolcache
|
|
|
|
# Set up environment paths and uv configuration
|
|
ENV AGENT_TOOLSDIRECTORY=/opt/hostedtoolcache \
|
|
UV_LINK_MODE=copy \
|
|
UV_NO_PROGRESS=true \
|
|
PATH="/root/.local/bin:/root/.cargo/bin:${PATH}"
|
|
|
|
## Layer: Node.js installation
|
|
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked,id=act-debian-apt-cache-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
--mount=type=cache,target=/var/lib/apt/lists,sharing=locked,id=act-debian-apt-lists-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
apt-get -qq update && apt-get -qq install -y --no-install-recommends \
|
|
npm \
|
|
&& apt-get clean
|
|
|
|
# Layer: uv, Python tools, git-annex
|
|
RUN --mount=type=cache,target=/root/.cache/uv,sharing=locked,id=act-debian-uv-cache-${DEBIAN_VERSION}-${TARGETARCH} \
|
|
curl -LsSf https://astral.sh/uv/install.sh | sh \
|
|
&& uv tool install prek \
|
|
&& uv tool install ruff \
|
|
&& uv tool install mypy \
|
|
&& uv tool install pytest \
|
|
&& uv tool install black \
|
|
&& uv tool install isort \
|
|
&& uv tool install hatch \
|
|
&& uv tool install git-annex
|
|
|
|
# Set up environment
|
|
ENV BUILDKIT_PROGRESS=plain \
|
|
CI=true \
|
|
DOCKER_BUILDKIT=1
|
|
|
|
WORKDIR /tmp
|
|
|
|
# Verify installations
|
|
RUN git --version && \
|
|
(command -v docker >/dev/null 2>&1 && docker --version || echo "Docker not installed") && \
|
|
python --version && \
|
|
uv --version && \
|
|
(command -v node >/dev/null 2>&1 && node --version || echo "Node.js not installed") && \
|
|
(command -v npm >/dev/null 2>&1 && npm --version || echo "npm not installed") && \
|
|
# Preload package lists and validate repositories
|
|
apt-get -qq update
|