forked from truespar/sentio
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
68 lines (53 loc) · 2.84 KB
/
Copy pathDockerfile
File metadata and controls
68 lines (53 loc) · 2.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
# syntax=docker/dockerfile:1.7
# ── Builder ──────────────────────────────────────────────────────────────
FROM rust:1-bookworm AS builder
WORKDIR /build
# aws-lc-rs (rustls backend) needs cmake + a C toolchain; build-essential is
# already present in the rust: image. libclang is only needed by some crates
# in the tree - install here rather than debugging a rebuild later.
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
cmake \
libclang-dev \
&& rm -rf /var/lib/apt/lists/*
COPY . .
# Use the committed .sqlx/ offline cache so the build doesn't need a live DB.
ENV SQLX_OFFLINE=true
# sentio-mcp rides along so the release job can lift both binaries out of the
# image instead of running a second set of release builds.
RUN cargo build --release -p sentio-smtp -p sentio-mcp --bins \
&& strip target/release/sentio-smtp target/release/sentio-mcp
# ── Runtime ──────────────────────────────────────────────────────────────
FROM debian:bookworm-slim AS runtime
LABEL org.opencontainers.image.title="Sentio SMTP" \
org.opencontainers.image.description="Email inbox API for AI agents: a multi-tenant mail server in Rust" \
org.opencontainers.image.source="https://github.com/truespar/sentio" \
org.opencontainers.image.licenses="MIT OR Apache-2.0"
RUN apt-get update \
&& apt-get install -y --no-install-recommends \
ca-certificates \
curl \
libcap2-bin \
tzdata \
&& rm -rf /var/lib/apt/lists/* \
&& groupadd --system --gid 1000 sentio \
&& useradd --system --uid 1000 --gid sentio \
--home-dir /var/lib/sentio --shell /usr/sbin/nologin sentio \
&& mkdir -p /etc/sentio /var/lib/sentio \
&& chown -R sentio:sentio /etc/sentio /var/lib/sentio
COPY --from=builder /build/target/release/sentio-smtp /usr/local/bin/sentio-smtp
COPY --from=builder /build/target/release/sentio-mcp /usr/local/bin/sentio-mcp
COPY --from=builder /build/migrations /usr/share/sentio/migrations
COPY config/oss.toml /etc/sentio/oss.toml
# Licence obligations travel with the binary, not just the repo.
COPY LICENSE LICENSE-MIT LICENSE-APACHE THIRD-PARTY-NOTICES.md \
/usr/share/doc/sentio/
# Allow the non-root user to bind :25/465/587 without full root.
RUN setcap 'cap_net_bind_service=+ep' /usr/local/bin/sentio-smtp
USER sentio
WORKDIR /var/lib/sentio
EXPOSE 25 465 587 8080 9090
HEALTHCHECK --interval=10s --timeout=5s --start-period=30s --retries=6 \
CMD curl -fsS http://localhost:8080/health/ready || exit 1
ENTRYPOINT ["/usr/local/bin/sentio-smtp"]
CMD ["--config", "/etc/sentio/oss.toml", "serve"]