From 06254e95a3453b9cde21e9ec483e63a6b5c36751 Mon Sep 17 00:00:00 2001 From: Mark Kalsbeek Date: Sat, 8 Aug 2026 16:27:50 +0200 Subject: [PATCH] Add Dockerfile and docker-compose for containerised deploys Multi-stage build: rust:1-slim-bookworm to compile (needs a recent toolchain per smarm/urus's MSRV), then a distroless/cc runtime image since the binary only links against glibc/libgcc/libm (checked via ldd) - no shell or package manager needed at runtime, ~27MB vs ~87MB for a debian-slim runtime. - CCC_DB_PATH defaults to /data/cdn.db in-container - docker-compose.yml persists /data in a named volume, maps 8333 --- .dockerignore | 3 +++ Dockerfile | 24 ++++++++++++++++++++++++ docker-compose.yml | 11 +++++++++++ 3 files changed, 38 insertions(+) create mode 100644 .dockerignore create mode 100644 Dockerfile create mode 100644 docker-compose.yml diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..1f5ab6c --- /dev/null +++ b/.dockerignore @@ -0,0 +1,3 @@ +target +*.db +.git diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..71215eb --- /dev/null +++ b/Dockerfile @@ -0,0 +1,24 @@ +# --- build stage --- +FROM rust:1-slim-bookworm AS builder +WORKDIR /build + +RUN apt-get update && apt-get install -y --no-install-recommends \ + build-essential pkg-config ca-certificates git \ + && rm -rf /var/lib/apt/lists/* + +COPY . . +RUN cargo build --release + +# --- runtime stage --- +# distroless/cc: just glibc + libgcc + libm, no shell/package manager. +# Matches what `ldd target/release/CCC` reports we actually need. +FROM gcr.io/distroless/cc-debian12 +WORKDIR /data + +COPY --from=builder /build/target/release/CCC /usr/local/bin/ccc + +ENV CCC_DB_PATH=/data/cdn.db +EXPOSE 8333 + +ENTRYPOINT ["/usr/local/bin/ccc"] +CMD ["serve", "--port", "8333"] diff --git a/docker-compose.yml b/docker-compose.yml new file mode 100644 index 0000000..16242f6 --- /dev/null +++ b/docker-compose.yml @@ -0,0 +1,11 @@ +services: + ccc: + build: . + ports: + - "8333:8333" + volumes: + - ccc-data:/data + restart: unless-stopped + +volumes: + ccc-data: