towerops-agent/Dockerfile
Graham McIntire 29b94c09d4
Fix segfault from Alpine version mismatch, add crash handler
The builder (rust:1.93-alpine) uses Alpine 3.23 but the runtime used
Alpine 3.19. The net-snmp-dev headers from 3.23 don't match
net-snmp-libs from 3.19, causing a segfault on the first SNMP call.

Also adds a SIGSEGV/SIGBUS/SIGABRT signal handler that prints a
diagnostic message instead of silently exiting with code 139.
2026-02-10 14:14:07 -06:00

76 lines
2.7 KiB
Docker

# syntax=docker/dockerfile:1.4
# Build stage
FROM rust:1.93-alpine AS builder
# Build arguments provided by Docker buildx
ARG TARGETPLATFORM
ARG TARGETARCH
ARG VERSION=0.1.0-unknown
WORKDIR /app
# Install build dependencies (net-snmp-dev required for C FFI)
RUN apk add --no-cache musl-dev protobuf-dev openssl-dev openssl-libs-static net-snmp-dev cmake perl g++
# Determine Rust target based on platform and add it
RUN case "$TARGETPLATFORM" in \
"linux/amd64") RUST_TARGET="x86_64-unknown-linux-musl" ;; \
"linux/arm64") RUST_TARGET="aarch64-unknown-linux-musl" ;; \
*) echo "Unsupported platform: $TARGETPLATFORM" && exit 1 ;; \
esac && \
echo "$RUST_TARGET" > /tmp/rust-target && \
rustup target add "$RUST_TARGET"
# Copy manifests and build files
COPY Cargo.toml Cargo.lock build.rs ./
COPY proto ./proto
COPY native ./native
# Create a dummy main.rs to build dependencies
RUN mkdir src && echo "fn main() {}" > src/main.rs
# Build dependencies (cached layer) with BuildKit cache mounts
# Cache is separated by target architecture for multi-platform builds
RUN --mount=type=cache,id=cargo-registry-${TARGETARCH},target=/usr/local/cargo/registry \
--mount=type=cache,id=cargo-git-${TARGETARCH},target=/usr/local/cargo/git \
--mount=type=cache,id=cargo-target-${TARGETARCH},target=/app/target \
RUST_TARGET=$(cat /tmp/rust-target) && \
BUILD_VERSION="$VERSION" cargo build --release --target "$RUST_TARGET"
# Remove dummy src
RUN rm -rf src
# Copy actual source code
COPY src ./src
# Build the actual application with BuildKit cache mounts
RUN --mount=type=cache,id=cargo-registry-${TARGETARCH},target=/usr/local/cargo/registry \
--mount=type=cache,id=cargo-git-${TARGETARCH},target=/usr/local/cargo/git \
--mount=type=cache,id=cargo-target-${TARGETARCH},target=/app/target \
RUST_TARGET=$(cat /tmp/rust-target) && \
touch src/main.rs && \
BUILD_VERSION="$VERSION" cargo build --release --target "$RUST_TARGET" && \
cp "target/$RUST_TARGET/release/towerops-agent" /tmp/towerops-agent
# Runtime stage - must match builder's Alpine version for ABI compatibility
# (rust:1.93-alpine uses Alpine 3.23)
FROM alpine:3.23
# Install runtime dependencies
# iputils provides ping with setuid root (doesn't require CAP_NET_RAW)
# net-snmp-libs required for C FFI to libnetsnmp
RUN apk add --no-cache ca-certificates iputils openssl net-snmp-libs
# Copy binary from builder
COPY --from=builder /tmp/towerops-agent /usr/local/bin/towerops-agent
# Create non-root user
RUN addgroup -g 1000 towerops && \
adduser -D -u 1000 -G towerops towerops
# Allow non-root user to overwrite binary during self-update
RUN chown towerops /usr/local/bin/towerops-agent
USER towerops
CMD ["towerops-agent"]