Decouple the privileged hardware poller from web iterations so a web
redeploy can never recreate/restart the poller (the backplane-touching
container). Two images from one Dockerfile via build targets:
- jbod-poller: privileged producer, ships smartmontools/sg3-utils/ledmon,
Redis-only deps (~197MB)
- jbod-web: unprivileged read-only consumer (REST/UI/MQTT), no hardware
tools, no /dev (~147MB)
Two compose projects sharing Redis over host networking:
- compose.infra.yml (jbod-infra): poller + redis — stable substrate
- compose.web.yml (jbod-web): app — 'up -d --build' touches only app
build.sh builds/pushes both images; split requirements-{poller,web}.txt;
dropped the combined docker-compose.yml; .dockerignore excludes tmp/ (keeps
the venv and the mqtt.env creds out of the build context).
31 lines
814 B
Bash
Executable File
31 lines
814 B
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
REG="docker.adamksmith.xyz"
|
|
|
|
cd "$(dirname "$0")"
|
|
|
|
# Stage and commit all changes
|
|
git add -A
|
|
if git diff --cached --quiet; then
|
|
echo "No changes to commit, using HEAD"
|
|
else
|
|
git commit -m "${1:-Build and push images}"
|
|
fi
|
|
|
|
SHA=$(git rev-parse --short HEAD)
|
|
|
|
# Two images from one Dockerfile (shared frontend build stage is cached):
|
|
# jbod-poller — privileged hardware producer
|
|
# jbod-web — unprivileged read-only consumer (REST/UI/MQTT)
|
|
for target in poller web; do
|
|
img="${REG}/jbod-${target}"
|
|
echo "Building ${img}:${SHA}"
|
|
docker build --target "${target}" -t "${img}:${SHA}" -t "${img}:latest" .
|
|
echo "Pushing ${img}:${SHA}"
|
|
docker push "${img}:${SHA}"
|
|
docker push "${img}:latest"
|
|
done
|
|
|
|
echo "Done: ${REG}/jbod-{poller,web}:${SHA}"
|