tidaldb/tidal/docker/deploy/Dockerfile
jx12n 3bcfb3c576 feat: Bazel build, crate docs/ai-lookup, docker images, and engine hardening
- Add BUILD.bazel across tidal, tidal-net, tidal-server, tidalctl for bzlmod build
- Add tidal/ crate docs (README, CHANGELOG, CONTRIBUTING, AGENTS, CLAUDE, API, ARCHITECTURE) and ai-lookup reference
- Add docker standalone/cluster/deploy images, compose, and prometheus config
- Harden WAL (batch format, writer, dedup, diagnostics), text syncer/collectors, and vector registry
- Expand tidalctl CLI and tests; restructure WAL/visibility integration test suites
- Refine tidal-net transport/client/server and tidal-server cluster/scatter-gather
2026-06-07 18:29:38 -06:00

65 lines
2.8 KiB
Docker

# Production single-node tidalDB deploy image (slim toolchain, durable /data).
#
# Build context is this repository's root (the workspace `Cargo.toml` /
# `Cargo.lock` and every member crate live there). Build from the repo root:
#
# docker build -f tidal/docker/deploy/Dockerfile -t tidaldb:deploy .
#
# The repo-root allowlist `.dockerignore` strips target/, node_modules/, .git,
# and .env* from the context, so `COPY . .` brings in exactly the workspace
# sources cargo needs to resolve the member graph and build `-p tidal-server`.
# Pin the builder to bookworm so its glibc matches the bookworm-slim runtime.
# The default slim tag tracks Debian trixie, whose vectorized-math
# `libmvec.so.1` is absent on bookworm and aborts the binary at startup.
FROM rust:1.91-slim-bookworm AS builder
ARG DEBIAN_FRONTEND=noninteractive
WORKDIR /build
# protobuf-compiler (protoc) is required by tidal-net's build script (tonic-build
# compiles the WAL-shipping .proto); tidal-server depends on tidal-net for gRPC
# cluster replication.
RUN apt-get update && apt-get install -y --no-install-recommends pkg-config libssl-dev g++ protobuf-compiler && rm -rf /var/lib/apt/lists/*
# Copy the full workspace and build only the server binary. The unified
# workspace requires every member manifest present to resolve metadata, so we
# copy the whole (already-pruned) context rather than a fragile manifest-only
# subset.
COPY . .
RUN cargo build -p tidal-server --release --locked
FROM debian:bookworm-slim
ARG DEBIAN_FRONTEND=noninteractive
RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates curl && rm -rf /var/lib/apt/lists/*
RUN useradd --system -u 10001 tidal
COPY --from=builder --chown=tidal:tidal /build/target/release/tidal-server /usr/local/bin/tidal-server
COPY --chown=tidal:tidal tidal-server/config /config
# Persistent data lives under /data, owned by the runtime user. Without this
# directory + the `--data-dir /data` flag below the server boots EPHEMERAL and
# loses every write on restart.
RUN mkdir -p /data && chown tidal:tidal /data
VOLUME ["/data"]
USER tidal:tidal
WORKDIR /data
EXPOSE 9400 9091
ENV TIDAL_SERVER_LOG=info
# Path the server reads its schema/topology from. The binary-side clap wiring
# for this lives in tidal-server (see sibling task T5); keep the name and
# default in sync with it here.
ENV TIDAL_CONFIG=/config
HEALTHCHECK --interval=30s --timeout=3s --start-period=10s --retries=3 \
CMD curl -sf http://localhost:9400/health || exit 1
# ENTRYPOINT is just the binary so `docker run tidaldb:deploy <subcommand>`
# overrides work. CMD carries the durable standalone invocation against the
# baked schema, persisting to the /data volume.
ENTRYPOINT ["tidal-server"]
CMD ["standalone", \
"--listen", "0.0.0.0:9400", \
"--schema", "/config/default-schema.yaml", \
"--data-dir", "/data", \
"--metrics", "0.0.0.0:9091"]