# This file is based on these images: # # - https://hub.docker.com/r/hexpm/elixir/tags - for the builder image # E.g.: docker.io/hexpm/elixir:1.20.1-erlang-29.0.2-debian-trixie-20260610-slim # - https://hub.docker.com/_/debian/tags?name=trixie-20260610-slim - for the runner image # E.g.: docker.io/debian:trixie-20260610-slim # # Find builder and runner images on Docker Hub or on Hex's Build Server (Bob). # We recommend using Bob's Web UI to find recent tags: # # - https://bob.hex.pm/docker # # We suggest using the same Debian version for both the builder and runner images. # # We suggest Debian/Ubuntu instead of Alpine to avoid production compatibility issues # (such as DNS resolution failures, and dynamically linked NIFs/precompiled binaries). # # For finding packages in Debian, search on https://packages.debian.org/. ARG ELIXIR_VERSION=1.20.1 ARG OTP_VERSION=29.0.2 ARG DEBIAN_VERSION=trixie-20260610-slim ARG BUILDER_IMAGE="docker.io/hexpm/elixir:${ELIXIR_VERSION}-erlang-${OTP_VERSION}-debian-${DEBIAN_VERSION}" ARG RUNNER_IMAGE="docker.io/debian:${DEBIAN_VERSION}" FROM ${BUILDER_IMAGE} AS builder # install build dependencies RUN apt-get update \ && apt-get install -y --no-install-recommends build-essential git \ && rm -rf /var/lib/apt/lists/* # prepare build dir WORKDIR /app # install hex + rebar RUN mix local.hex --force \ && mix local.rebar --force # set build ENV ENV MIX_ENV="prod" # install mix dependencies COPY mix.exs mix.lock ./ RUN mix deps.get --only $MIX_ENV RUN mkdir config # copy compile-time config files before we compile dependencies # to ensure any relevant config change will trigger the dependencies # to be re-compiled. COPY config/config.exs config/${MIX_ENV}.exs config/ RUN mix deps.compile RUN mix assets.setup COPY priv priv COPY lib lib # Compile the release RUN mix compile COPY assets assets # compile assets RUN mix assets.deploy # Changes to config/runtime.exs don't require recompiling the code COPY config/runtime.exs config/ COPY rel rel RUN mix release # start a new build stage so that the final image will only contain # the compiled release and other runtime necessities FROM ${RUNNER_IMAGE} AS final # git: Tarakan shells out to git for pinned-commit snapshots, blobless # mirrors, and smart-HTTP/SSH hosting — it must be present at runtime. # openssh-client: Tarakan.GitSSH.Server generates its ed25519 host key with # ssh-keygen on first boot. Without it the daemon fails to start, and # because that failure stops a supervised child, the whole release # refuses to boot rather than merely losing SSH. # tini: reaps the many short-lived git subprocesses so they don't become # zombies. RUN apt-get update \ && apt-get install -y --no-install-recommends libstdc++6 openssl libncurses6 locales ca-certificates git openssh-client tini \ && rm -rf /var/lib/apt/lists/* # Set the locale RUN sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen \ && locale-gen ENV LANG=en_US.UTF-8 ENV LANGUAGE=en_US:en ENV LC_ALL=en_US.UTF-8 WORKDIR "/app" RUN chown nobody /app # Persistent storage for hosted repositories, the mirror hot-tier, and the SSH # host key. These are mounted as volumes in production; creating them owned by # nobody means a fresh named volume inherits writable ownership. ssh is 0700 # because ssh-keygen refuses to use a key whose directory is group-readable. RUN mkdir -p /app/storage/mirrors /app/storage/hosted /app/storage/ssh \ && chmod 700 /app/storage/ssh \ && chown -R nobody /app/storage # set runner ENV ENV MIX_ENV="prod" # Only copy the final release from the build stage COPY --from=builder --chown=nobody:root /app/_build/${MIX_ENV}/rel/tarakan ./ USER nobody # tini reaps zombie git subprocesses. ENTRYPOINT ["/usr/bin/tini", "--"] CMD ["/app/bin/server"]