Repository navigation
Conversation
Two self-contained images, built from new stages of the Dockerfile: "php" (php-fpm with the code, the vendors and the compiled assets baked in, APP_ENV=prod, also the CLI image for the cron job and the migrations) and "nginx" (the official image with the compiled public/ directory). They talk through the php-fpm unix socket shared via a volume, and run as non-root users. Everything else (secrets, database, Slack and Google credentials) comes from environment variables at runtime, and public/uploads must be a shared volume. The php-fpm and nginx configuration is now shared between the dev "frontend" container and the production images (php/, nginx/), the production-only differences living in php/mods-available/app-prod.ini. The dev php-fpm listens on the same unix socket, and the dev container exposes port 8080. A "prod" castor context runs the usual tasks on a dedicated compose stack (castor build|start|destroy -c prod) to test the images locally, and `castor docker:push --tag=...` also pushes the images themselves. The "Build and push production images" workflow does so on every push to main and on every tag, tagging the images with the short commit sha, "latest" on main, and the tag name.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ships the application as two self-contained Docker images, built and pushed to GHCR by the CI on every push to
mainand on every tag:php: php-fpm listening on the unix socket/var/run/php/php-fpm.sock, with the code, the vendors and the compiled assets baked in,APP_ENV=prod. It is also the CLI image (bin/console) for the cron job and the migrations.nginx: the official nginx image with the compiledpublic/directory and the site configuration, forwarding PHP requests to that socket.Both run as non-root users. Everything else (secrets, database, Slack and Google credentials) is provided through environment variables at runtime, and
public/uploadsmust be a volume shared by all the containers.Other changes:
frontendcontainer and the production images (services/php/fpm/,services/php/nginx/); the production-only differences live inservices/php/prod/. The dev php-fpm listens on the same unix socket, and the dev container exposes port 8080;prodcastor context runs the usual tasks on a dedicated compose stack, to test the images locally:castor build -c prod,castor start -c prod,castor destroy -c prod(see the README);castor docker:pushcan also push the images themselves with--tag, which is what the new "Build and push production images" workflow does. Images are tagged with the short commit sha,latestonmain, and the git tag when there is one.