-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathDockerfile
More file actions
40 lines (39 loc) · 1.86 KB
/
Copy pathDockerfile
File metadata and controls
40 lines (39 loc) · 1.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
# p2p container image. Native cross-compile: the build stage runs on the
# builder's architecture (BUILDPLATFORM) and produces a TARGETOS/TARGETARCH
# binary, so CI does not pay for QEMU-emulated Go compilation -- only the
# lightweight alpine runtime stage runs under QEMU.
FROM --platform=$BUILDPLATFORM golang:1.27-alpine3.23 AS build
# No defaults: BuildKit populates these from the target platform (both for
# `buildx --platform` and plain `docker build`). A default SHADOWS that value --
# `ARG TARGETARCH=amd64` silently put an amd64 binary inside the arm64 image,
# which then failed at startup with "exec format error".
ARG TARGETOS
ARG TARGETARCH
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
go build -ldflags="-s -w" -o /p2p ./cmd/p2p
# Runtime environment. Non-root (uid 10001) by default.
#
# No device or capability is needed: this host only bridges tunnels and, for a
# datagram channel, binds a loopback UDP endpoint. tun/tap belongs to GOST --
# the tun listener creates and configures the device and needs
# CAP_NET_ADMIN + /dev/net/tun in *its* container, not in this one.
#
# The DERP key persists by mounting the home directory, the way the derper
# image is run: `-v key:/home/p2p`, with the key at the default
# $HOME/.config/p2p/key-v1 (no --key needed). adduser creates that home owned
# by p2p, so a fresh volume seeds from it with the right ownership. Do not
# invent a second mount path for the key: a volume mounted where the image has
# no such directory is created root:root, and this non-root user then cannot
# write the key at all.
FROM alpine:3.23
RUN apk add --no-cache ca-certificates \
&& adduser -D -u 10001 p2p
COPY --from=build /p2p /usr/local/bin/p2p
USER p2p
# gRPC control plane (stub mode). DERP mode is outbound, no port to expose.
EXPOSE 8003
ENTRYPOINT ["/usr/local/bin/p2p"]