FROM debian:buster-slim as nsjail WORKDIR /nsjail ARG nsjail="" RUN if [ "$nsjail" = "true" ]; then apt-get -y update \ && apt-get install -y \ bison=2:3.3.* \ flex=2.6.* \ g++=4:8.3.* \ gcc=4:8.3.* \ git=1:2.20.* \ libprotobuf-dev=3.6.* \ libnl-route-3-dev=3.4.* \ make=4.2.* \ pkg-config=0.29-6 \ protobuf-compiler=3.6.*; fi RUN if [ "$nsjail" = "true" ]; then git clone -b master --single-branch https://github.com/google/nsjail.git . \ && git checkout dccf911fd2659e7b08ce9507c25b2b38ec2c5800; fi RUN if [ "$nsjail" = "true" ]; then make; else touch nsjail; fi FROM rust:slim-buster AS rust_base RUN apt-get update && apt-get install -y git libssl-dev pkg-config npm RUN apt-get -y update \ && apt-get install -y \ curl lld nodejs npm RUN rustup component add rustfmt RUN CARGO_NET_GIT_FETCH_WITH_CLI=true cargo install cargo-chef WORKDIR /windmill ENV SQLX_OFFLINE=true ENV CARGO_INCREMENTAL=1 FROM node:20-alpine as frontend # install dependencies WORKDIR /frontend COPY ./frontend/package.json ./frontend/package-lock.json ./ RUN npm ci # Copy all local files into the image. COPY frontend . RUN mkdir /backend COPY /backend/windmill-api/openapi.yaml /backend/windmill-api/openapi.yaml COPY /openflow.openapi.yaml /openflow.openapi.yaml COPY /backend/windmill-api/build_openapi.sh /backend/windmill-api/build_openapi.sh RUN cd /backend/windmill-api && . ./build_openapi.sh RUN npm run generate-backend-client ENV NODE_OPTIONS "--max-old-space-size=8192" RUN npm run build RUN npm run check FROM rust_base AS planner COPY ./openflow.openapi.yaml /openflow.openapi.yaml COPY ./backend ./ RUN CARGO_NET_GIT_FETCH_WITH_CLI=true cargo chef prepare --recipe-path recipe.json FROM rust_base AS builder ARG features="" COPY --from=planner /windmill/recipe.json recipe.json RUN CARGO_NET_GIT_FETCH_WITH_CLI=true RUST_BACKTRACE=1 cargo chef cook --release --features "$features" --recipe-path recipe.json COPY ./openflow.openapi.yaml /openflow.openapi.yaml COPY ./backend ./ COPY --from=frontend /frontend /frontend COPY --from=frontend /backend/windmill-api/openapi-deref.yaml ./windmill-api/openapi-deref.yaml COPY .git/ .git/ RUN CARGO_NET_GIT_FETCH_WITH_CLI=true cargo build --release --features "$features" FROM python:3.11.3-slim-buster ARG TARGETPLATFORM ARG APP=/usr/src/app RUN apt-get update \ && apt-get install -y ca-certificates wget curl git jq libprotobuf-dev libnl-route-3-dev unzip \ && apt-get install -y ca-certificates wget curl git jq libprotobuf-dev libnl-route-3-dev unzip build-essential \ && rm -rf /var/lib/apt/lists/* RUN arch="$(dpkg --print-architecture)"; arch="${arch##*-}"; \ curl -o rclone.zip "https://downloads.rclone.org/v1.60.1/rclone-v1.60.1-linux-$arch.zip"; \ unzip -p rclone.zip rclone-v1.60.1-linux-$arch/rclone > /usr/bin/rclone; rm rclone.zip; \ chown root:root /usr/bin/rclone; chmod 755 /usr/bin/rclone RUN set -eux; \ arch="$(dpkg --print-architecture)"; arch="${arch##*-}"; \ url=; \ case "$arch" in \ 'amd64') \ targz='go1.19.3.linux-amd64.tar.gz'; \ ;; \ 'arm64') \ targz='go1.19.3.linux-arm64.tar.gz'; \ ;; \ 'armhf') \ targz='go1.19.3.linux-armv6l.tar.gz'; \ ;; \ *) echo >&2 "error: unsupported architecture '$arch' (likely packaging update needed)"; exit 1 ;; \ esac; \ wget "https://golang.org/dl/$targz" -nv && tar -C /usr/local -xzf "$targz" && rm "$targz"; ENV PATH="${PATH}:/usr/local/go/bin" ENV GO_PATH=/usr/local/go/bin/go ENV TZ=Etc/UTC RUN /usr/local/bin/python3 -m pip install pip-tools COPY --from=frontend /frontend/build /static_frontend COPY --from=builder /windmill/target/release/windmill ${APP}/windmill COPY --from=nsjail /nsjail/nsjail /bin/nsjail COPY --from=denoland/deno:1.33.3 /usr/bin/deno /usr/bin/deno # docker does not support conditional COPY and we want to use the same Dockerfile for both amd64 and arm64 and privilege the official image COPY --from=lukechannings/deno:v1.33.3 /usr/bin/deno /usr/bin/deno-arm RUN if [ "$TARGETPLATFORM" = "linux/amd64" ]; then rm /usr/bin/deno-arm; elif [ "$TARGETPLATFORM" = "linux/arm64" ]; then mv /usr/bin/deno-arm /usr/bin/deno; fi # add the docker client to call docker from a worker if enabled COPY --from=docker:dind /usr/local/bin/docker /usr/local/bin/ RUN mkdir -p ${APP} RUN ln -s ${APP}/windmill /usr/local/bin/windmill WORKDIR ${APP} EXPOSE 8000 CMD ["windmill"]