-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.multiarch
More file actions
81 lines (56 loc) · 2.83 KB
/
Copy pathDockerfile.multiarch
File metadata and controls
81 lines (56 loc) · 2.83 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
FROM docker.io/node:24-alpine@sha256:d32cdf619f63fe0471182d08996dd516c6275bb5fd31ae06e55a570bd9e1ad43 AS frontend-builder
ARG GIT_REF="main"
# Optional exact commit to build. When set (rolling builds), it pins the clone to
# that commit and, because it is referenced in the clone layer below, busts the
# build cache whenever upstream main moves so the rolling image stays fresh.
# Leave empty to clone GIT_REF as-is.
ARG GIT_SHA=""
RUN apk add --no-cache git
RUN npm install -g pnpm@10.34.1
RUN git clone --depth 1 --branch "${GIT_REF}" https://github.com/owncloud/ocis-workflows.git /build && \
if [ -n "${GIT_SHA}" ]; then \
git -C /build fetch --depth 1 origin "${GIT_SHA}" && \
git -C /build checkout --detach FETCH_HEAD; \
fi
WORKDIR /build/frontend
RUN pnpm install --frozen-lockfile && pnpm build
FROM docker.io/golang:1.27-alpine@sha256:8a5910f31396cd4d89662f56c68b3ae31d374308270a1c3bd96672ee5ed43414 AS go-builder
ARG TARGETARCH
RUN apk add --no-cache git
COPY --from=frontend-builder /build /build
WORKDIR /build/backend
RUN go mod download && \
CGO_ENABLED=0 GOOS=linux GOARCH=${TARGETARCH} go build -o /out/app ./cmd/workflows
FROM docker.io/alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6
ARG VERSION=""
ARG REVISION=""
LABEL maintainer="ownCloud GmbH <devops@owncloud.com>" \
org.opencontainers.image.title="oCIS Workflows" \
org.opencontainers.image.vendor="ownCloud GmbH" \
org.opencontainers.image.authors="ownCloud GmbH" \
org.opencontainers.image.description="oCIS Workflows - AI-powered file workflow automation extension for ownCloud Infinite Scale" \
org.opencontainers.image.licenses="Apache-2.0" \
org.opencontainers.image.documentation="https://github.com/owncloud/ocis-workflows" \
org.opencontainers.image.url="https://hub.docker.com/r/owncloud/ocis-workflows" \
org.opencontainers.image.source="https://github.com/owncloud/ocis-workflows" \
org.opencontainers.image.version="${VERSION:-main-${REVISION}}" \
org.opencontainers.image.revision="${REVISION}"
RUN apk upgrade --no-cache && \
apk add --no-cache ca-certificates
RUN addgroup -g 1000 -S workflows-group && \
adduser -S --ingroup workflows-group --uid 1000 workflows-user --home /data
RUN mkdir -p /data && \
chown -R workflows-user:workflows-group /data && \
chmod -R 751 /data
COPY --from=go-builder /out/app /usr/local/bin/app
# Baked-in web extension assets. Not served by this image directly — copy this
# path into your oCIS deployment's WEB_ASSET_APPS_PATH (e.g. via an
# initContainer running `cp`), the same way docker-compose.yml in the app repo
# mounts frontend/dist into the oCIS container.
COPY --from=frontend-builder /build/frontend/dist /web/apps/workflows
VOLUME [ "/data" ]
WORKDIR /data
EXPOSE 9105/tcp 9109/tcp
USER 1000
ENTRYPOINT ["/usr/local/bin/app"]
CMD ["server"]