amber-backend/Dockerfile

44 lines
1.6 KiB
Docker
Raw Normal View History

# myanime-backend — PocketBase, version-pinned from the official release.
#
# We download the official static binary from GitHub releases (rather than a
# third-party image) so the deploy is reproducible and easy to audit.
FROM alpine:3.20 AS fetch
# Bump this to upgrade PocketBase. Keep it in sync with the README.
ARG PB_VERSION=0.39.6
ARG TARGETARCH=amd64
RUN apk add --no-cache ca-certificates unzip wget \
&& wget -q "https://github.com/pocketbase/pocketbase/releases/download/v${PB_VERSION}/pocketbase_${PB_VERSION}_linux_${TARGETARCH}.zip" -O /tmp/pb.zip \
&& unzip /tmp/pb.zip -d /pb \
&& rm /tmp/pb.zip
FROM alpine:3.20
RUN apk add --no-cache ca-certificates
COPY --from=fetch /pb/pocketbase /usr/local/bin/pocketbase
# Schema-as-code: migrations are baked in and auto-applied on serve.
COPY pb_migrations /pb_migrations
# JS hooks (custom routes + the device sign-in approve page, issue #12). Loaded
# from --hooksDir on serve.
COPY pb_hooks /pb_hooks
# Static distribution/onboarding site (landing + account wizard) served at /.
COPY pb_public /pb_public
# Persist DB, uploaded files, and any admin-created migrations here. Runs as root
# so it can always write the volume Coolify attaches — Coolify's persistent mount
# is root-owned, and a non-root user hitting it fails with SQLite "unable to open
# database file (14)".
RUN mkdir -p /pb_data
VOLUME ["/pb_data"]
EXPOSE 8090
# Coolify terminates TLS at Traefik; PocketBase listens plain on 8090 behind it.
ENTRYPOINT ["pocketbase"]
CMD ["serve", "--http=0.0.0.0:8090", "--dir=/pb_data", "--migrationsDir=/pb_migrations", "--hooksDir=/pb_hooks", "--publicDir=/pb_public"]