From 438bffc26ed9d82994c0cf12e7d3d5387e4b5079 Mon Sep 17 00:00:00 2001 From: "devin-ai-integration[bot]" <158243242+devin-ai-integration[bot]@users.noreply.github.com> Date: Sun, 27 Sep 2026 16:49:39 -0700 Subject: [PATCH] build(rust): package the gateway container (#43471) * build(rust): package the gateway container * ci: exempt the gateway Dockerfile from the CI coverage gate Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Yujong Lee Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .github/ci-coverage-allowlist.yml | 7 +++ litellm-rust/crates/gateway/Dockerfile | 47 +++++++++++++++++++ .../crates/gateway/Dockerfile.dockerignore | 9 ++++ 3 files changed, 63 insertions(+) create mode 100644 litellm-rust/crates/gateway/Dockerfile create mode 100644 litellm-rust/crates/gateway/Dockerfile.dockerignore diff --git a/.github/ci-coverage-allowlist.yml b/.github/ci-coverage-allowlist.yml index 69d9f427212..445a8519436 100644 --- a/.github/ci-coverage-allowlist.yml +++ b/.github/ci-coverage-allowlist.yml @@ -111,3 +111,10 @@ dockerfiles: An example image under cookbook/ that is documentation rather than a shipped artifact paths: - cookbook/litellm-ollama-docker-image/Dockerfile + - reason: >- + The Rust gateway image compiles the whole workspace in release mode, which is too slow for + a per-pull-request job while the gateway binary is still being assembled; the Rust lint, + clippy, and compile jobs already cover the code it packages. Revisit when the gateway is + published + paths: + - litellm-rust/crates/gateway/Dockerfile diff --git a/litellm-rust/crates/gateway/Dockerfile b/litellm-rust/crates/gateway/Dockerfile new file mode 100644 index 00000000000..72008ee5f26 --- /dev/null +++ b/litellm-rust/crates/gateway/Dockerfile @@ -0,0 +1,47 @@ +FROM rust:1.98.0-bookworm@sha256:82150a52ec202c1b14d7817e14516c392bb7f5cfebd88f1ed531cb37ebd39922 AS chef + +RUN apt-get update \ + && apt-get install --yes --no-install-recommends cmake \ + && rm -rf /var/lib/apt/lists/* + +RUN cargo install cargo-chef --version 0.1.74 --locked + +WORKDIR /app + +FROM chef AS planner + +COPY Cargo.toml Cargo.lock ./ +COPY crates ./crates + +RUN cargo chef prepare --recipe-path recipe.json + +FROM chef AS builder + +COPY --from=planner /app/recipe.json ./recipe.json + +RUN --mount=type=cache,target=/usr/local/cargo/registry,sharing=locked \ + cargo chef cook --release --locked --package litellm-gateway --bin litellm-gateway --recipe-path recipe.json + +COPY Cargo.toml Cargo.lock ./ +COPY crates ./crates + +RUN --mount=type=cache,target=/usr/local/cargo/registry,sharing=locked \ + cargo build --release --locked --package litellm-gateway --bin litellm-gateway + +FROM debian:bookworm-slim@sha256:3783cc01769c7b2b1b83a5c5ad96c815348e28ed7da68e2e3687004faa906251 AS runtime + +RUN apt-get update \ + && apt-get install --yes --no-install-recommends ca-certificates \ + && rm -rf /var/lib/apt/lists/* \ + && groupadd --gid 10001 litellm \ + && useradd --uid 10001 --gid litellm --no-create-home --shell /usr/sbin/nologin litellm + +WORKDIR /app + +COPY --from=builder /app/target/release/litellm-gateway /usr/local/bin/litellm-gateway + +USER 10001:10001 + +EXPOSE 4000 + +ENTRYPOINT ["/usr/local/bin/litellm-gateway"] diff --git a/litellm-rust/crates/gateway/Dockerfile.dockerignore b/litellm-rust/crates/gateway/Dockerfile.dockerignore new file mode 100644 index 00000000000..229cc1c4c66 --- /dev/null +++ b/litellm-rust/crates/gateway/Dockerfile.dockerignore @@ -0,0 +1,9 @@ +** +!Cargo.toml +!Cargo.lock +!crates/ +!crates/** +**/.env +**/.env.* +**/target/ +**/.DS_Store