mirror of
https://github.com/thegeneralist01/archivr
synced 2026-07-22 03:05:32 +02:00
fix: address second round of Docker review issues
Chromium sandbox (P2): - singlefile.rs: add ARCHIVR_CHROME_ARGS env var (space-separated flags appended to Chromium's --browser-args JSON array); Dockerfile sets it to --no-sandbox because Chromium refuses to start as root without it Store-path outside volume (P1): - README: pass explicit absolute store-path as the second positional arg to `archivr init` so the blob store lands on /data instead of the container layer (CLI default is ./.archivr/store, resolved from cwd, which is / with no WORKDIR set) ENTRYPOINT vs CMD (P2): - Dockerfile: switch from ENTRYPOINT to CMD so `docker compose run archivr archivr init …` overrides the full command instead of being appended to the server invocation ffmpeg missing (P2): - Dockerfile: add ffmpeg to the apt-get install block (required by yt-dlp --merge-output-format mp4 for bestvideo+bestaudio streams) Node version (P2): - Dockerfile: replace Debian bookworm's nodejs (18.x) with Node 20 via the NodeSource setup script (single-file-cli declares engines.node >=20) Build context secrets (P2): - Add .dockerignore excluding config/ and docker/ from the build context so runtime secrets (e.g. twitter-cookies.txt) are never sent to the builder - Whitelist .dockerignore in .gitignore docs: - README: document ARCHIVR_CHROME_ARGS in the Environment Variables section
This commit is contained in:
parent
38d3066ee4
commit
93dea9ffbf
5 changed files with 47 additions and 11 deletions
21
Dockerfile
21
Dockerfile
|
|
@ -44,18 +44,24 @@ FROM debian:bookworm-slim
|
|||
|
||||
# Runtime dependencies:
|
||||
# chromium used by single-file-cli for full-page archiving
|
||||
# nodejs + npm runtime for single-file-cli
|
||||
# nodejs (20+) runtime for single-file-cli (requires Node >=20; Debian
|
||||
# bookworm ships 18, so we install from the NodeSource repo)
|
||||
# ffmpeg required by yt-dlp to merge separate audio/video streams
|
||||
# (e.g. YouTube bestvideo+bestaudio format selection)
|
||||
# python3 + pip + venv twitter scraper
|
||||
# ca-certificates outbound HTTPS from the server
|
||||
# ca-certificates outbound HTTPS from the server and NodeSource HTTPS
|
||||
# libssl3 OpenSSL linked by the Rust binary
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
curl \
|
||||
ca-certificates \
|
||||
&& curl -fsSL https://deb.nodesource.com/setup_20.x | bash - \
|
||||
&& apt-get install -y --no-install-recommends \
|
||||
chromium \
|
||||
nodejs \
|
||||
npm \
|
||||
ffmpeg \
|
||||
python3 \
|
||||
python3-pip \
|
||||
python3-venv \
|
||||
ca-certificates \
|
||||
libssl3 \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
|
|
@ -88,10 +94,13 @@ ENV ARCHIVR_STATIC_DIR=/usr/share/archivr-server/static \
|
|||
ARCHIVR_SINGLE_FILE=/usr/local/bin/single-file \
|
||||
ARCHIVR_TWEET_PYTHON=/opt/archivr-venv/bin/python3 \
|
||||
ARCHIVR_TWEET_SCRAPER=/usr/local/lib/archivr/scrape_user_tweet_contents.py \
|
||||
ARCHIVR_YT_DLP=/opt/archivr-venv/bin/yt-dlp
|
||||
ARCHIVR_YT_DLP=/opt/archivr-venv/bin/yt-dlp \
|
||||
ARCHIVR_CHROME_ARGS=--no-sandbox
|
||||
|
||||
EXPOSE 8080
|
||||
|
||||
# Expects the TOML config at /config/archivr-server.toml (mount a volume).
|
||||
# Copy docker/config.example.toml as a starting point.
|
||||
ENTRYPOINT ["archivr-server", "/config/archivr-server.toml"]
|
||||
# Using CMD (not ENTRYPOINT) so `docker compose run archivr archivr init …`
|
||||
# can override the whole command for first-time archive initialisation.
|
||||
CMD ["archivr-server", "/config/archivr-server.toml"]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue