Created
July 13, 2026 08:38
-
-
Save bogdan/f65fe1c0fb6d66effebfef9541b36c72 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # syntax=docker/dockerfile:1 | |
| # check=error=true;skip=SecretsUsedInArgOrEnv | |
| # This Dockerfile is designed for production, not development. Use with Kamal or build'n'run by hand: | |
| # docker build -t realphotos_marketplace . | |
| # docker run -d -p 80:80 -e RAILS_MASTER_KEY=<value from config/master.key> --name realphotos_marketplace realphotos_marketplace | |
| # For a containerized dev environment, see Dev Containers: https://guides.rubyonrails.org/getting_started_with_devcontainer.html | |
| # Make sure RUBY_VERSION matches the Ruby version in .ruby-version | |
| ARG RUBY_VERSION=4.0.1 | |
| FROM docker.io/library/ruby:$RUBY_VERSION-slim AS base | |
| # Rails app lives here | |
| WORKDIR /rails | |
| # Install base packages | |
| # curl - downloading files at runtime (e.g. health checks) | |
| # libjemalloc2 - memory allocator with lower fragmentation and better performance | |
| # libvips - image processing backend for Active Storage variants | |
| # postgresql-client - psql CLI for database management and health checks | |
| RUN apt-get update -qq && \ | |
| apt-get install --no-install-recommends -y curl libjemalloc2 libvips postgresql-client && \ | |
| rm -rf /var/lib/apt/lists /var/cache/apt/archives | |
| # Set production environment | |
| ENV RAILS_ENV="production" \ | |
| BUNDLE_DEPLOYMENT="1" \ | |
| BUNDLE_PATH="/usr/local/bundle" \ | |
| BUNDLE_WITHOUT="development" | |
| # Throw-away build stage to reduce size of final image | |
| FROM base AS build | |
| # Install packages needed to build gems and frontend assets | |
| # build-essential - C/C++ compiler and make for compiling native gem extensions | |
| # git - required by Bundler to install gems from git sources | |
| # pkg-config - helps native extensions locate system libraries during compilation | |
| # libpq-dev - PostgreSQL headers required to compile the pg gem | |
| # libyaml-dev - YAML headers required to compile the psych gem (Ruby's YAML parser) | |
| # automake, libtool, libffi-dev, libssl-dev, libgmp-dev - required by rbsecp256k1 (eth gem dependency) | |
| # liborc-0.4-dev - ORC (SIMD optimization) headers required by libvips build pipeline | |
| # libglib2.0-dev - GLib headers required by libvips | |
| # nodejs / npm - JavaScript runtime needed to run Vite for asset compilation | |
| # corepack - enables Yarn 4 (defined in packageManager field) via Node's Corepack | |
| RUN apt-get update -qq && \ | |
| apt-get install --no-install-recommends -y build-essential git pkg-config libpq-dev libyaml-dev automake libtool libffi-dev libssl-dev libgmp-dev liborc-0.4-dev libglib2.0-dev nodejs npm && \ | |
| corepack enable && \ | |
| rm -rf /var/lib/apt/lists /var/cache/apt/archives | |
| # Install application gems | |
| COPY Gemfile Gemfile.lock ./ | |
| RUN bundle install && \ | |
| rm -rf ~/.bundle/ "${BUNDLE_PATH}"/ruby/*/cache "${BUNDLE_PATH}"/ruby/*/bundler/gems/*/.git && \ | |
| bundle exec bootsnap precompile --gemfile | |
| # Copy application code | |
| COPY . . | |
| # Precompile bootsnap code for faster boot times | |
| RUN bundle exec bootsnap precompile app/ lib/ | |
| # Precompiling assets for production without requiring secret RAILS_MASTER_KEY | |
| RUN SECRET_KEY_BASE_DUMMY=1 ./bin/rails assets:precompile | |
| # Final stage for app image | |
| FROM base | |
| ARG MASTER_KEY | |
| ENV RAILS_MASTER_KEY=${MASTER_KEY} | |
| # Copy built artifacts: gems, application | |
| COPY --from=build "${BUNDLE_PATH}" "${BUNDLE_PATH}" | |
| COPY --from=build /rails /rails | |
| # Run and own only the runtime files as a non-root user for security | |
| RUN groupadd --system --gid 1000 rails && \ | |
| useradd rails --uid 1000 --gid 1000 --create-home --shell /bin/bash && \ | |
| chown -R rails:rails db log storage tmp | |
| USER 1000:1000 | |
| # Entrypoint prepares the database. | |
| ENTRYPOINT ["/rails/bin/docker-entrypoint"] | |
| # Start server via Thruster by default, this can be overwritten at runtime | |
| EXPOSE 80 | |
| CMD ["./bin/thrust", "./bin/rails", "server"] |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment