# syntax=docker/dockerfile:1 # --- Build stage ------------------------------------------------------------- # Compile a static Go binary. The Vue panel is pre-built into internal/api/dist # and embedded via //go:embed, so no Node toolchain is needed here. FROM golang:1.26-alpine3.24 AS build WORKDIR /src # Cache module downloads separately from the source for faster rebuilds. COPY go.mod ./ # go.sum is optional (stdlib-only module today); copy it if present. COPY go.su[m] ./ RUN go mod download COPY . . # CGO_ENABLED=0 produces a static binary that runs on a bare alpine image. The # entry point is the cmd/server package. RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-s -w" -o /out/api-server ./cmd/server # --- Runtime stage ----------------------------------------------------------- FROM alpine:3.24 # HTTPS calls to PocketBase need CA certificates; tzdata for correct timestamps. # su-exec lets the entrypoint fix /data ownership as root and then drop to app. RUN apk add --no-cache ca-certificates tzdata su-exec # Run as an unprivileged user. RUN addgroup -S app && adduser -S -G app app COPY --from=build /out/api-server /usr/local/bin/api-server # The server writes .env relative to its working directory — the panel rewrites # it when a superadmin retargets the PocketBase connection — and reads a legacy # plugins.json from there once, to import it into the database. So the working # directory must be writable and persistent: hence /data, owned by the # unprivileged user and declared as a volume. A fresh named volume inherits this # ownership. (Plugin settings themselves live in PocketBase, not here.) RUN mkdir -p /data && chown app:app /data WORKDIR /data VOLUME /data # A fresh named volume inherits /data's ownership, but two common cases do not: # a host bind mount (API_DATA=/srv/... in docker-compose.prod.yml) arrives owned # by root, and so does a volume created by an image from before /data existed, # when the server ran with a root-owned working directory. In both cases the # unprivileged process cannot write .env, so retargeting PocketBase from the # panel silently fails to stick across a restart. The entrypoint therefore starts # as root purely to fix ownership, then drops to app. RUN cat > /entrypoint.sh <<'ENTRY' #!/bin/sh set -e if [ "$(id -u)" = "0" ]; then mkdir -p /data if [ "$(stat -c %U /data 2>/dev/null)" != "app" ]; then echo "entrypoint: taking ownership of /data" chown -R app:app /data fi exec su-exec app "$@" fi # Already unprivileged (docker run --user ...): nothing to drop, just run. exec "$@" ENTRY RUN chmod +x /entrypoint.sh # Config comes entirely from environment variables (see .env.example). # POCKETBASE_ADMIN_EMAIL / _PASSWORD are optional at startup: without them the # server still runs and a superadmin can configure the connection from the panel. # PLUGINS_FILE is only the one-time import path for a pre-PocketBase install; # the settings themselves live in the database. ENV API_ADDR=:8080 \ PLUGINS_FILE=/data/plugins.json EXPOSE 8080 # Liveness only: /healthz answers 200 as soon as the process is serving, and # does not depend on PocketBase, so a database outage does not mark the # container unhealthy. Lets compose gate dependants on condition: service_healthy. HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \ CMD wget -qO- http://127.0.0.1:8080/healthz >/dev/null 2>&1 || exit 1 # The entrypoint drops to the unprivileged app user after fixing /data. ENTRYPOINT ["/entrypoint.sh"] CMD ["/usr/local/bin/api-server"]