This repository was archived by the owner on Aug 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
123 lines (102 loc) · 5.41 KB
/
Copy pathDockerfile
File metadata and controls
123 lines (102 loc) · 5.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
# ─── Stage 1: Build C++ libraries ────────────────────────────────────────────
FROM debian:trixie-slim AS cpp-builder
RUN apt-get update && apt-get install -y --no-install-recommends \
build-essential cmake git ca-certificates python3 \
&& rm -rf /var/lib/apt/lists/*
# OR-Tools and HiGHS are built with the build dir as a subdir of the source
# tree (e.g. /build/ortools/build). The Rust sys crates rely on this layout:
# their build.rs sets ortools_src = ortools_build.parent().
ARG ORTOOLS_TAG=v9.15
RUN git clone --depth 1 --branch ${ORTOOLS_TAG} \
https://github.com/google/or-tools /build/ortools && \
cmake -S /build/ortools -B /build/ortools/build \
-DCMAKE_BUILD_TYPE=Release \
-DBUILD_DEPS=ON \
-DBUILD_SHARED_LIBS=ON \
-DBUILD_EXAMPLES=OFF \
-DBUILD_TESTS=OFF \
-DUSE_GLOP=ON \
-DUSE_CP_SAT=ON \
-DUSE_SCIP=OFF \
-DUSE_COINOR=OFF && \
cmake --build /build/ortools/build --target ortools -j"$(nproc)"
ARG HIGHS_TAG=v1.14.0
RUN git clone --depth 1 --branch ${HIGHS_TAG} \
https://github.com/ERGO-Code/HiGHS /build/highs && \
cmake -S /build/highs -B /build/highs/build \
-DCMAKE_BUILD_TYPE=Release \
-DBUILD_SHARED_LIBS=ON \
-DFAST_BUILD=ON && \
cmake --build /build/highs/build -j"$(nproc)"
# ─── Stage 2: Compile Rust server ────────────────────────────────────────────
FROM rust:1.94-trixie AS rust-builder
RUN apt-get update && apt-get install -y --no-install-recommends \
build-essential cmake clang libclang-dev protobuf-compiler git ca-certificates \
&& rm -rf /var/lib/apt/lists/*
# Bring full source + build trees so the sys crates' build.rs finds headers
# under the source root and libs/_deps under the build dir.
COPY --from=cpp-builder /build/ortools /opt/ortools
COPY --from=cpp-builder /build/highs /opt/highs
WORKDIR /workspace
# Build context is the ferrox repo root.
COPY . /workspace/
# [patch.crates-io] in Cargo.toml references sibling repos via the
# developer-monorepo layout (`../../bedrock-platform/converge/...`,
# `../../bedrock-platform/organism/...`). The Docker build context only
# includes ferrox-solvers, so those paths don't resolve.
#
# Approach (mirrors marquee-apps/quorum-sense/deploy/backend/Dockerfile.cloudrun):
# clone the sibling repos to /bedrock-platform/<name> and sed-rewrite the
# patch paths to point at the clones. This keeps ferrox's source on the
# same converge-pack/organism API surface it was authored against —
# crucial when ferrox uses APIs not yet published to crates.io
# (e.g., ProvenanceSource::proposed_fact_for added post-3.9.2).
RUN mkdir -p /bedrock-platform && \
git clone --depth=1 --quiet https://github.com/Reflective-Lab/converge.git /bedrock-platform/converge && \
git clone --depth=1 --quiet https://github.com/Reflective-Lab/organism.git /bedrock-platform/organism
RUN sed -i \
-e 's|path = "../../bedrock-platform/|path = "/bedrock-platform/|g' \
/workspace/Cargo.toml && \
rm -f /workspace/Cargo.lock
ENV FERROX_ORTOOLS_ROOT=/opt/ortools/build
ENV FERROX_HIGHS_ROOT=/opt/highs/build
# HiGHS v1.14.0+ moved headers from src/ to highs/. The published
# ferrox-highs-sys build.rs still includes <root>/src; bridge with a symlink.
RUN [ -d /opt/highs/src ] || ln -s /opt/highs/highs /opt/highs/src
# OR-Tools BUILD_SHARED_LIBS=ON splits abseil into separate .so files. The
# published ortools-sys build.rs only emits `-lortools`, so absl::log_internal
# symbols pulled in via headers (e.g. ortools/util/bitset.h) are unresolved.
# Discover every libabsl_*.so + protobuf companions in the OR-Tools build and
# expose them via RUSTFLAGS. -L is included so build scripts (which inherit
# RUSTFLAGS) can resolve the lib names; ld's default --as-needed then skips
# them in build-script binaries that don't reference the symbols.
RUN set -eux; \
cd /opt/ortools/build/lib; \
ABSL_FLAGS=$(ls libabsl_*.so 2>/dev/null \
| sed -E 's|^lib([^.]+)\.so$|-Clink-arg=-l\1|' | tr '\n' ' '); \
PROTOBUF_FLAGS=$(ls libprotobuf*.so libutf8_*.so libre2*.so 2>/dev/null \
| sed -E 's|^lib([^.]+)\.so$|-Clink-arg=-l\1|' | tr '\n' ' '); \
cd /workspace; \
RUSTFLAGS="-L /opt/ortools/build/lib $ABSL_FLAGS $PROTOBUF_FLAGS" \
cargo build --release \
--package converge-ferrox-server --features converge-ferrox-server/full
# ─── Stage 3: Minimal runtime ────────────────────────────────────────────────
FROM debian:trixie-slim AS runtime
RUN apt-get update && apt-get install -y --no-install-recommends \
libstdc++6 ca-certificates \
&& rm -rf /var/lib/apt/lists/*
# Copy all shared libs OR-Tools produces (libortools.so + libabsl_*.so +
# libprotobuf*.so + utf8_range, re2 …) so the binary can resolve them at
# runtime. Same for HiGHS.
COPY --from=cpp-builder /build/ortools/build/lib/*.so* /usr/local/lib/
COPY --from=cpp-builder /build/highs/build/lib/*.so* /usr/local/lib/
RUN ldconfig
COPY --from=rust-builder \
/workspace/target/release/ferrox-server \
/usr/local/bin/ferrox-server
VOLUME ["/tls"]
EXPOSE 50051
ENV FERROX_ADDR=0.0.0.0:50051
ENV FERROX_TLS_CERT=/tls/server.crt
ENV FERROX_TLS_KEY=/tls/server.key
ENTRYPOINT ["/usr/local/bin/ferrox-server"]