mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-08-28 05:27:41 +00:00
Now that the release workflow publishes musl binaries, the runtime image can drop the debian:trixie-slim base for alpine:3.22. The image shrinks from ~287 MB to ~96 MB (66% smaller) with a smaller attack surface. - Dockerfile: alpine:3.22 base, apk packages (ca-certificates git tini su-exec), BusyBox adduser/addgroup, tini at /sbin/tini. - entrypoint.sh: replace runuser with su-exec, Alpine's idiomatic drop-privileges helper. - release.yml docker job: pull the two linux-musl artifacts instead of linux-gnu. The docker image and the Alpine install.sh path now ship the same binary. - bin/dev/docker-build.sh: compile fabro-cli for the host's musl target in rust:1-bookworm with musl-tools, the matching CC/LINKER env vars, and LIBZ_SYS_STATIC=1. Same pattern as CI. Verified locally on aarch64: Alpine image builds, server binds on $PORT (default 32276), endpoints return 200, fabro server process runs as unprivileged UID 1000 under tini. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Dockerfile.agent | ||
| entrypoint.sh | ||
| settings.toml | ||