Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 36 additions & 18 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,32 +1,50 @@
FROM rust:1.95.0-bookworm AS builder
# syntax=docker/dockerfile:1

ARG GIT_COMMIT_HASH_SHORT
ENV GIT_COMMIT_HASH_SHORT=${GIT_COMMIT_HASH_SHORT}

ARG SOURCE_DATE_EPOCH
ENV SOURCE_DATE_EPOCH=${SOURCE_DATE_EPOCH}
# Digest pinned 2026-07-27.
FROM rust:slim-bookworm@sha256:99e09cb2284e2ddbb73a995deee3e91783fd04d177602ccf6eab326d778ee777 AS chef

RUN apt-get update && \
apt-get install -y pkg-config \
openssl libssl-dev \
protobuf-compiler=3.21.12*
apt-get install -y --no-install-recommends \
pkg-config \
libssl-dev \
protobuf-compiler=3.21.12-3 && \
rm -rf /var/lib/apt/lists/*

RUN cargo install cargo-chef --locked --version 0.1.77

WORKDIR /build

# `rustup show` installs the toolchain pinned in rust-toolchain.toml.
COPY rust-toolchain.toml .
RUN rustup show

RUN --mount=type=cache,target=/usr/local/cargo/registry \
--mount=type=cache,target=/usr/local/cargo/git \
cargo install oas3-gen@0.24.0
FROM chef AS planner
COPY . .
RUN cargo chef prepare --recipe-path recipe.json

FROM chef AS builder

RUN cargo install oas3-gen --locked --version 0.24.0

# No cache mounts: compiled deps must live in image layers for CI's `cache-to: type=gha` to persist them (gha stores layers, not mounts).
COPY --from=planner /build/recipe.json recipe.json
RUN cargo chef cook --locked --release --package pluto-cli --recipe-path recipe.json

# These change every commit; declared after the cook step so they don't invalidate the dependency layer above.
ARG GIT_COMMIT_HASH_SHORT
ENV GIT_COMMIT_HASH_SHORT=${GIT_COMMIT_HASH_SHORT}

ARG SOURCE_DATE_EPOCH
ENV SOURCE_DATE_EPOCH=${SOURCE_DATE_EPOCH}

COPY . .
RUN --mount=type=cache,target=/usr/local/cargo/registry \
--mount=type=cache,target=/usr/local/cargo/git \
--mount=type=cache,target=/build/target \
cargo build --locked --release --package pluto-cli && \
cp /build/target/release/pluto /usr/local/bin/pluto
# `rm -rf target` keeps this per-commit layer at ~binary size in the gha cache.
RUN cargo build --locked --release --package pluto-cli && \
cp /build/target/release/pluto /usr/local/bin/pluto && \
rm -rf /build/target

FROM gcr.io/distroless/cc-debian13 AS app
# Digest pinned 2026-07-27.
FROM gcr.io/distroless/cc-debian13@sha256:ed7c407fd64eb0af9dddb9456b94cee188a40a7f53cf38c9836e1e9ae14fca02 AS app

COPY --from=builder /usr/local/bin/pluto /app/bin/pluto

Expand Down