R2D2-MERIDIAN/Dockerfile.push-gateway
Joshua Belke 6c261c9117
Some checks failed
control plane / chart (push) Has been cancelled
control plane / test (push) Has been cancelled
control plane / browser-e2e (push) Has been cancelled
control plane / Build control plane image (linux/amd64) (push) Has been cancelled
control plane / Build control plane image (linux/arm64) (push) Has been cancelled
control plane / Publish signed control plane image (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Meridian Harness / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Meridian Harness / Publish rolling release (push) Has been cancelled
Meridian Harness / Publish tagged release (push) Has been cancelled
Harbor Meridian Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Server Cross-Compile (push) Has been cancelled
CI / Server Cross-Compile-1 (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
fix(repo): point the repo slug at the real remote, not the guessed one
The rebrand baked in `github.com/r2d2/meridian`, chosen before the remote
existed. The canonical remote is `git.office.ilab.zone/RAID/R2D2-MERIDIAN` — a
different host, org, and repo name. ~150 references move: OCI image.source
labels, Helm chart sources, CI repository vars, Cargo `repository` metadata,
NIP-11 `software`, the docs and release scripts.

The container registry is unchanged and confirmed correct:
`registry.r2d2.office.ilab.zone`.

Three sets are deliberately left on github.com:

- **The link-preview fixtures.** `linkPreview.ts` gates on
  `normalizeHostname(parsed) !== "github.com"`, so the 33 URLs in
  `linkPreview.test.mjs` and two e2e specs are exercising a GitHub
  link-preview *feature*, not this repo's identity. Repointing them at a host
  the parser rejects would have turned passing tests red for no reason.
- **`raw.githubusercontent.com/aaif-goose/…`**, which is the third-party Goose
  installer.
- **Two API-shaped URLs** — the Releases API in `web/src/shared/lib/
  meridian-download.ts` and the raw-file URL in
  `managed_agents/discovery.rs`. Gitea/Forgejo spells these differently
  (`/api/v1/repos/…` with `limit=` and a different payload;
  `/raw/branch/<ref>/<path>`), so swapping only the host yields a URL that
  404s *while looking correct*. Neither endpoint could be probed, so both keep
  a `DANGLING` marker and are tracked in meridian-kir rather than guessed at.
  The download path already fails soft: a non-ok response falls back to
  `MERIDIAN_RELEASES_URL`, which now resolves to the Gitea releases page.

The discovery.rs marker is a one-line trailing comment because that file is
already over the size ratchet and may not grow — the explanation lives in the
bead, which is where it belongs. Line count is unchanged at 1858.

Verified: just ci exit 0.
Signed-off-by: Joshua Belke <joshua@innovationhub-act.org>
2026-08-05 13:00:51 -04:00

37 lines
1.5 KiB
Text

# syntax=docker/dockerfile:1.7
ARG RUST_VERSION=1.95
ARG DEBIAN_VERSION=bookworm
FROM rust:${RUST_VERSION}-${DEBIAN_VERSION} AS chef
RUN cargo install cargo-chef --locked --version 0.1.71
WORKDIR /build
FROM chef AS planner
COPY . .
RUN cargo chef prepare --recipe-path recipe.json
FROM chef AS builder
RUN apt-get update \
&& apt-get install -y --no-install-recommends build-essential pkg-config libssl-dev ca-certificates \
&& rm -rf /var/lib/apt/lists/*
COPY --from=planner /build/recipe.json recipe.json
RUN cargo chef cook --release --recipe-path recipe.json
COPY . .
RUN cargo build --release --locked -p meridian-push-gateway --bin meridian-push-gateway \
&& strip target/release/meridian-push-gateway
FROM debian:${DEBIAN_VERSION}-slim AS runtime
LABEL org.opencontainers.image.title="Meridian Push Gateway" \
org.opencontainers.image.description="Capability-gated APNs last hop for Meridian" \
org.opencontainers.image.source="https://git.office.ilab.zone/RAID/R2D2-MERIDIAN" \
org.opencontainers.image.licenses="Apache-2.0"
RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates \
&& rm -rf /var/lib/apt/lists/* \
&& groupadd --system --gid 1000 meridian \
&& useradd --system --uid 1000 --gid 1000 --home-dir /var/lib/meridian --create-home --shell /usr/sbin/nologin meridian
COPY --from=builder /build/target/release/meridian-push-gateway /usr/local/bin/meridian-push-gateway
EXPOSE 8080 8081
USER meridian:meridian
WORKDIR /var/lib/meridian
ENTRYPOINT ["/usr/local/bin/meridian-push-gateway"]