mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-02 23:06:36 +08:00
Merge branch 'wavelet/main' into main
This commit is contained in:
@@ -1,55 +0,0 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
# Agent image: slim binary + MMDB files on disk (not embedded in the binary).
|
||||
ARG VERSION=dev
|
||||
|
||||
FROM golang:1.25-alpine AS builder
|
||||
|
||||
ARG VERSION
|
||||
ARG TARGETOS=linux
|
||||
ARG TARGETARCH
|
||||
|
||||
ENV CGO_ENABLED=0 \
|
||||
GOOS=${TARGETOS} \
|
||||
GOARCH=${TARGETARCH}
|
||||
|
||||
WORKDIR /build
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
go mod download
|
||||
|
||||
COPY backend/ ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
--mount=type=cache,target=/root/.cache/go-build \
|
||||
go build -trimpath -ldflags "-s -w -X 'Wavelet/openflare/plugins/agent/config.Version=$VERSION'" -o /build/bin/openflare-agent ./cmd/agent/main.go
|
||||
|
||||
# Fetch MMDB into dist/geoip for COPY into the runtime image (not go:embed).
|
||||
RUN apk add --no-cache bash curl \
|
||||
&& bash scripts/fetch-agent-geoip-mmdb.sh
|
||||
|
||||
FROM openresty/openresty:alpine
|
||||
|
||||
RUN apk add --no-cache ca-certificates tzdata perl libmaxminddb su-exec libcap \
|
||||
&& ln -sf /usr/lib/libmaxminddb.so.0 /usr/lib/libmaxminddb.so \
|
||||
&& opm get anjia0532/lua-resty-maxminddb \
|
||||
&& addgroup -S openflare \
|
||||
&& adduser -S -G openflare -H -h /data -s /sbin/nologin openflare \
|
||||
&& mkdir -p /etc/openflare /data/etc/openflare \
|
||||
&& chown -R openflare:openflare /etc/openflare /data \
|
||||
&& setcap 'cap_net_bind_service=+ep' /usr/local/openresty/nginx/sbin/nginx
|
||||
|
||||
ENV OPENFLARE_OPENRESTY_PATH=openresty \
|
||||
OPENFLARE_DATA_DIR=/data
|
||||
|
||||
COPY --from=builder /build/bin/openflare-agent /usr/local/bin/openflare-agent
|
||||
# Default agent paths: data_dir/etc/openflare/GeoLite2-*.mmdb
|
||||
COPY --from=builder /build/dist/geoip/GeoLite2-Country.mmdb /data/etc/openflare/GeoLite2-Country.mmdb
|
||||
COPY --from=builder /build/dist/geoip/GeoLite2-City.mmdb /data/etc/openflare/GeoLite2-City.mmdb
|
||||
RUN chown openflare:openflare /data/etc/openflare/GeoLite2-Country.mmdb /data/etc/openflare/GeoLite2-City.mmdb \
|
||||
&& chmod 644 /data/etc/openflare/GeoLite2-Country.mmdb /data/etc/openflare/GeoLite2-City.mmdb
|
||||
|
||||
COPY scripts/agent-entrypoint.sh /usr/local/bin/openflare-agent-entrypoint.sh
|
||||
RUN chmod +x /usr/local/bin/openflare-agent-entrypoint.sh
|
||||
|
||||
EXPOSE 80 443 18081
|
||||
ENTRYPOINT ["/usr/local/bin/openflare-agent-entrypoint.sh"]
|
||||
CMD ["-config", "/etc/openflare/agent.json"]
|
||||
@@ -1,42 +0,0 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
|
||||
ARG GO_VERSION=1.25
|
||||
ARG ALPINE_VERSION=3.23
|
||||
|
||||
FROM golang:${GO_VERSION}-alpine AS builder
|
||||
|
||||
ARG VERSION=dev
|
||||
ARG BUILD_DATE=""
|
||||
|
||||
RUN apk add --no-cache ca-certificates git
|
||||
|
||||
WORKDIR /workspace
|
||||
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
COPY backend/ ./
|
||||
|
||||
RUN CGO_ENABLED=0 GOOS=linux go build \
|
||||
-trimpath \
|
||||
-ldflags="-s -w -X Wavelet/pkg/buildinfo.Version=${VERSION} -X Wavelet/pkg/buildinfo.BuildTime=${BUILD_DATE}" \
|
||||
-o /out/openflare-server \
|
||||
./main.go
|
||||
|
||||
FROM alpine:${ALPINE_VERSION}
|
||||
|
||||
ARG TZ=Asia/Shanghai
|
||||
|
||||
RUN apk add --no-cache ca-certificates tzdata postgresql-client && \
|
||||
cp /usr/share/zoneinfo/${TZ} /etc/localtime && \
|
||||
echo "${TZ}" > /etc/timezone
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY --from=builder /out/openflare-server ./openflare-server
|
||||
COPY docs ./docs
|
||||
|
||||
EXPOSE 3000
|
||||
|
||||
ENTRYPOINT ["./openflare-server"]
|
||||
CMD ["api"]
|
||||
@@ -1,114 +0,0 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
# Cross-platform build workflow — produces up to 6 static binaries under ./bin/
|
||||
# Each binary embeds the compiled frontend and is stamped with VERSION.
|
||||
#
|
||||
# Build args:
|
||||
# VERSION — version string injected at link time (default: dev)
|
||||
# TARGET_OS — restrict to one OS: linux | darwin | windows (default: all)
|
||||
# TARGET_ARCH — restrict to one arch: amd64 | arm64 (default: all)
|
||||
#
|
||||
# Usage:
|
||||
# docker build -f docker/Dockerfile.cross --output ./bin .
|
||||
# docker build -f docker/Dockerfile.cross \
|
||||
# --build-arg VERSION=v1.2.3 --output ./bin .
|
||||
# docker build -f docker/Dockerfile.cross \
|
||||
# --build-arg TARGET_OS=linux --build-arg TARGET_ARCH=arm64 \
|
||||
# --output ./bin .
|
||||
#
|
||||
# Or via Makefile:
|
||||
# make cross-build
|
||||
# make cross-build VERSION=v1.2.3
|
||||
# make cross-build GOOS=linux GOARCH=arm64
|
||||
# make cross-build GOOS=darwin
|
||||
|
||||
ARG GO_VERSION=1.25
|
||||
ARG NODE_VERSION=22
|
||||
ARG ALPINE_VERSION=3.23
|
||||
|
||||
# ── Stage 1: Build frontend (static export for embedding) ────────────────────
|
||||
FROM node:${NODE_VERSION}-alpine AS frontend-builder
|
||||
|
||||
ARG VERSION=dev
|
||||
ARG BUILD_DATE=""
|
||||
|
||||
ENV PNPM_HOME="/pnpm"
|
||||
ENV PATH="$PNPM_HOME:$PATH"
|
||||
ENV NODE_ENV=production
|
||||
ENV NEXT_STANDALONE_EXPORT=true
|
||||
ENV NEXT_PUBLIC_APP_VERSION=${VERSION}
|
||||
ENV NEXT_PUBLIC_APP_BUILD_DATE=${BUILD_DATE}
|
||||
|
||||
RUN corepack enable && corepack prepare pnpm@10.10.0 --activate
|
||||
|
||||
WORKDIR /workspace/frontend
|
||||
|
||||
# Cache dependency layer
|
||||
COPY frontend/package.json frontend/pnpm-lock.yaml frontend/pnpm-workspace.yaml ./
|
||||
RUN pnpm install --frozen-lockfile
|
||||
|
||||
COPY frontend/ ./
|
||||
|
||||
# Assert index.html so a silent export failure cannot ship API-only binaries.
|
||||
RUN pnpm build:embed && test -f out/index.html
|
||||
|
||||
# ── Stage 2: Cross-compile Go backend ──────────────────────────────────────
|
||||
FROM golang:${GO_VERSION}-alpine${ALPINE_VERSION} AS builder
|
||||
|
||||
ARG VERSION=dev
|
||||
ARG BUILD_DATE=""
|
||||
# Empty string means "build all"; set to a specific value to filter.
|
||||
ARG TARGET_OS=
|
||||
ARG TARGET_ARCH=
|
||||
|
||||
# git — needed by go mod download for VCS-stamped modules
|
||||
# ca-certificates — needed for HTTPS during module download
|
||||
RUN apk add --no-cache ca-certificates git
|
||||
|
||||
WORKDIR /workspace
|
||||
|
||||
# Cache dependency layer
|
||||
COPY backend/go.mod backend/go.sum ./backend/
|
||||
RUN cd backend && go mod download
|
||||
|
||||
COPY . .
|
||||
|
||||
# Drop any stale bundle carried in the context, then overlay the fresh export so
|
||||
# `//go:embed all:dist` in driver_http picks up exactly this frontend build.
|
||||
RUN rm -rf backend/plugins/drivers/driver_http/dist
|
||||
COPY --from=frontend-builder /workspace/frontend/out backend/plugins/drivers/driver_http/dist
|
||||
|
||||
WORKDIR /workspace/backend
|
||||
|
||||
# Build matrix: GOOS × GOARCH
|
||||
# CGO_ENABLED=0 — fully static, no libc dependency, required for cross-compilation.
|
||||
# -trimpath — strip local filesystem paths from the binary.
|
||||
# -s -w — omit symbol table and DWARF debug info (smaller output).
|
||||
# -X — stamp version string at link time.
|
||||
# TARGET_OS / TARGET_ARCH — when non-empty, skip non-matching combinations.
|
||||
RUN set -e; \
|
||||
test -f plugins/drivers/driver_http/dist/index.html; \
|
||||
mkdir -p /out; \
|
||||
FILTER_OS="${TARGET_OS}"; \
|
||||
FILTER_ARCH="${TARGET_ARCH}"; \
|
||||
for GOOS in linux darwin windows; do \
|
||||
[ -n "$FILTER_OS" ] && [ "$GOOS" != "$FILTER_OS" ] && continue; \
|
||||
for GOARCH in amd64 arm64; do \
|
||||
[ -n "$FILTER_ARCH" ] && [ "$GOARCH" != "$FILTER_ARCH" ] && continue; \
|
||||
EXT=""; \
|
||||
[ "$GOOS" = "windows" ] && EXT=".exe"; \
|
||||
OUTPUT="/out/openflare-server_${GOOS}_${GOARCH}${EXT}"; \
|
||||
echo "==> Building ${OUTPUT} (version=${VERSION})..."; \
|
||||
CGO_ENABLED=0 GOOS=${GOOS} GOARCH=${GOARCH} \
|
||||
go build \
|
||||
-tags embed_frontend \
|
||||
-trimpath \
|
||||
-ldflags="-s -w -X Wavelet/pkg/buildinfo.Version=${VERSION} -X Wavelet/pkg/buildinfo.BuildTime=${BUILD_DATE}" \
|
||||
-o "${OUTPUT}" \
|
||||
./main.go; \
|
||||
done; \
|
||||
done
|
||||
|
||||
# ── Export stage ─────────────────────────────────────────────────────────────
|
||||
# `docker build --output ./bin .` copies everything from /out to the host.
|
||||
FROM scratch AS export
|
||||
COPY --from=builder /out/ /
|
||||
@@ -1,30 +0,0 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
ARG VERSION=dev
|
||||
|
||||
FROM golang:1.25-alpine AS builder
|
||||
|
||||
ARG VERSION
|
||||
|
||||
WORKDIR /build
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
go mod download
|
||||
|
||||
COPY backend/ ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
--mount=type=cache,target=/root/.cache/go-build \
|
||||
CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags "-s -w -X 'Wavelet/openflare/plugins/flared/config.Version=$VERSION'" -o flared ./cmd/flared/main.go
|
||||
|
||||
# Final runtime image
|
||||
FROM fatedier/frpc:v0.69.0
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Copy openflared binary
|
||||
COPY --from=builder /build/flared .
|
||||
|
||||
ENV OPENFLARE_DATA_DIR=/app/data
|
||||
ENV OPENFLARE_FRPC_PATH=/usr/bin/frpc
|
||||
|
||||
ENTRYPOINT ["/app/flared"]
|
||||
CMD []
|
||||
@@ -1,53 +0,0 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
|
||||
ARG NODE_VERSION=22
|
||||
|
||||
FROM node:${NODE_VERSION}-alpine AS base
|
||||
|
||||
ENV PNPM_HOME="/pnpm"
|
||||
ENV PATH="$PNPM_HOME:$PATH"
|
||||
|
||||
RUN corepack enable && corepack prepare pnpm@10.10.0 --activate
|
||||
|
||||
FROM base AS builder
|
||||
|
||||
ENV NODE_ENV=production
|
||||
ENV NEXT_PUBLIC_WAVELET_BACKEND_URL=https://build-placeholder.invalid
|
||||
ENV WAVELET_SESSION_COOKIE_NAME=__WAVELET_SESSION_COOKIE_NAME__
|
||||
ENV WAVELET_RATE_LIMIT_ENABLED=__WAVELET_RATE_LIMIT_ENABLED__
|
||||
ENV WAVELET_BACKEND_URL=https://build-placeholder-2.invalid
|
||||
|
||||
ARG VERSION=""
|
||||
ARG BUILD_DATE=""
|
||||
|
||||
ENV NEXT_PUBLIC_APP_VERSION=${VERSION}
|
||||
ENV NEXT_PUBLIC_APP_BUILD_DATE=${BUILD_DATE}
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY frontend/package.json frontend/pnpm-lock.yaml ./
|
||||
RUN pnpm install --frozen-lockfile
|
||||
|
||||
COPY frontend/ ./
|
||||
|
||||
RUN pnpm build
|
||||
|
||||
RUN grep -rl \
|
||||
-e "https://build-placeholder.invalid" \
|
||||
-e "https://build-placeholder-2.invalid" \
|
||||
-e "__WAVELET_SESSION_COOKIE_NAME__" \
|
||||
-e "__WAVELET_RATE_LIMIT_ENABLED__" \
|
||||
/app/.next > /app/.replace.files
|
||||
|
||||
FROM base AS runner
|
||||
|
||||
ENV NODE_ENV=production
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY --from=builder /app ./
|
||||
|
||||
EXPOSE 3010
|
||||
|
||||
ENTRYPOINT ["./entrypoint.sh"]
|
||||
CMD ["pnpm", "start"]
|
||||
@@ -1,31 +0,0 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
ARG VERSION=dev
|
||||
|
||||
FROM golang:1.25-alpine AS builder
|
||||
|
||||
ARG VERSION
|
||||
|
||||
WORKDIR /build
|
||||
COPY backend/go.mod backend/go.sum ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
go mod download
|
||||
|
||||
COPY backend/ ./
|
||||
RUN --mount=type=cache,target=/go/pkg/mod \
|
||||
--mount=type=cache,target=/root/.cache/go-build \
|
||||
CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags "-s -w -X 'Wavelet/openflare/plugins/relay/config.Version=$VERSION'" -o /build/bin/openflare-relay ./cmd/relay/main.go
|
||||
|
||||
# Final runtime image
|
||||
FROM fatedier/frps:v0.69.0
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Copy openflare-relay binary
|
||||
COPY --from=builder /build/bin/openflare-relay ./openflare-relay
|
||||
|
||||
VOLUME ["/app/data"]
|
||||
|
||||
ENV OPENFLARE_FRPS_PATH=/usr/bin/frps
|
||||
ENV OPENFLARE_DATA_DIR=/app/data
|
||||
|
||||
ENTRYPOINT ["/app/openflare-relay"]
|
||||
Reference in New Issue
Block a user