# Copyright 2024 RustFS Team # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. FROM ubuntu:26.04 AS build ARG TARGETARCH ARG RELEASE=latest RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates \ curl \ jq \ unzip \ && rm -rf /var/lib/apt/lists/* WORKDIR /build RUN set -eux; \ case "$TARGETARCH" in \ amd64) ARCH_SUBSTR="x86_64-gnu" ;; \ arm64) ARCH_SUBSTR="aarch64-gnu" ;; \ *) echo "Unsupported TARGETARCH=$TARGETARCH" >&2; exit 1 ;; \ esac; \ if [ "$RELEASE" = "latest" ]; then \ RELEASE_JSON="$(curl -fsSL https://api.github.com/repos/rustfs/rustfs/releases | jq -c '.[0]')"; \ TAG="$(printf '%s' "$RELEASE_JSON" | jq -r '.tag_name // empty')"; \ else \ TAG="$RELEASE"; \ RELEASE_JSON="$(curl -fsSL "https://api.github.com/repos/rustfs/rustfs/releases/tags/$TAG" 2>/dev/null || true)"; \ if [ -z "$RELEASE_JSON" ]; then \ if [ "${TAG#v}" = "$TAG" ]; then \ ALT_TAG="v$TAG"; \ else \ ALT_TAG="${TAG#v}"; \ fi; \ echo "Primary tag lookup failed, retrying with alternate tag: $ALT_TAG"; \ RELEASE_JSON="$(curl -fsSL "https://api.github.com/repos/rustfs/rustfs/releases/tags/$ALT_TAG")"; \ TAG="$ALT_TAG"; \ fi; \ fi; \ if [ -z "$TAG" ] || [ -z "$RELEASE_JSON" ]; then echo "Failed to resolve release metadata" >&2; exit 1; fi; \ echo "Using tag: $TAG (arch pattern: $ARCH_SUBSTR)"; \ ASSET_JSON="$(printf '%s' "$RELEASE_JSON" | jq -c --arg arch "$ARCH_SUBSTR" '.assets[] | select((.name | contains($arch)) and (.name | endswith(".zip"))) | {name: .name, url: .browser_download_url, digest: .digest}' | head -n 1)"; \ if [ -z "$ASSET_JSON" ]; then echo "Failed to locate release asset for $ARCH_SUBSTR at tag $TAG" >&2; exit 1; fi; \ ASSET_NAME="$(printf '%s' "$ASSET_JSON" | jq -r '.name // empty')"; \ URL="$(printf '%s' "$ASSET_JSON" | jq -r '.url // empty')"; \ DIGEST="$(printf '%s' "$ASSET_JSON" | jq -r '.digest // empty')"; \ SHA256="$(printf '%s' "$DIGEST" | sed 's/^sha256://')"; \ \ if [ -z "$URL" ] || [ -z "$ASSET_NAME" ]; then echo "Failed to locate release asset for $ARCH_SUBSTR at tag $TAG" >&2; exit 1; fi; \ if [ -z "$SHA256" ] || [ "$SHA256" = "$DIGEST" ]; then echo "Release asset $ASSET_NAME is missing a sha256 digest" >&2; exit 1; fi; \ \ curl -fL "$URL" -o rustfs.zip; \ printf '%s rustfs.zip\n' "$SHA256" | sha256sum -c -; \ unzip -q rustfs.zip -d /build; \ \ if [ ! -x /build/rustfs ]; then \ BIN_PATH="$(unzip -Z -1 rustfs.zip | grep -E '(^|/)rustfs$' | head -n 1 || true)"; \ if [ -n "$BIN_PATH" ]; then \ mkdir -p /build/.tmp && unzip -q rustfs.zip "$BIN_PATH" -d /build/.tmp && \ mv "/build/.tmp/$BIN_PATH" /build/rustfs; \ fi; \ fi; \ [ -x /build/rustfs ] || { echo "rustfs binary not found in asset" >&2; exit 1; }; \ chmod +x /build/rustfs; \ rm -rf rustfs.zip /build/.tmp || true FROM ubuntu:26.04 ARG RELEASE=latest ARG BUILD_DATE ARG VCS_REF LABEL name="RustFS" \ vendor="RustFS Team" \ maintainer="RustFS Team " \ version="v${RELEASE#v}" \ release="${RELEASE}" \ build-date="${BUILD_DATE}" \ vcs-ref="${VCS_REF}" \ summary="High-performance distributed object storage system (glibc)" \ url="https://rustfs.com" \ license="Apache-2.0" # Upgrade base-image packages so published images pick up security fixes # (e.g. tar/gzip/perl CVEs) without waiting for a new Ubuntu point release. RUN apt-get update && apt-get upgrade -y \ && apt-get install -y --no-install-recommends \ ca-certificates \ curl \ && rm -rf /var/lib/apt/lists/* COPY --from=build /build/rustfs /usr/bin/rustfs COPY entrypoint.sh /entrypoint.sh RUN chmod +x /usr/bin/rustfs /entrypoint.sh RUN groupadd -g 10001 rustfs && \ useradd -u 10001 -g rustfs -m -s /sbin/nologin rustfs && \ mkdir -p /data /logs && \ chown -R rustfs:rustfs /data /logs && \ chmod 0750 /data /logs ENV RUSTFS_ADDRESS=":9000" \ RUSTFS_CONSOLE_ADDRESS=":9001" \ RUSTFS_CONSOLE_ENABLE="true" \ RUSTFS_CONSOLE_CORS_ALLOWED_ORIGINS="*" \ RUSTFS_VOLUMES="/data" \ RUSTFS_OBS_LOGGER_LEVEL=warn \ RUSTFS_OBS_LOG_DIRECTORY=/logs \ RUSTFS_OBS_ENVIRONMENT=production EXPOSE 9000 9001 VOLUME ["/data"] USER rustfs ENTRYPOINT ["/entrypoint.sh"] CMD ["rustfs"]