# Two stages: the runtime image carries the binary and nothing else. # Must match the `go` directive in go.mod. A lower builder fails with # "go.mod requires go >= X" because GOTOOLCHAIN=local inside the image - the # local build hid this by silently downloading a newer toolchain. FROM golang:1.25-alpine AS build WORKDIR /src COPY go.mod go.sum ./ RUN go mod download COPY . . ARG VERSION=dev # CGO off gives a static binary, which is what makes the scratch-like runtime # below possible and removes the whole class of glibc/musl surprises. RUN CGO_ENABLED=0 GOOS=linux go build -trimpath \ -ldflags "-s -w -X main.version=${VERSION}" \ -o /out/behavision-server ./cmd/behavision-server FROM alpine:3.20 # ca-certificates for outbound TLS (object storage, webhooks). tzdata because # footfall is reported in each site's local time and the container's default # UTC-only image would make every report an hour or more wrong. RUN apk add --no-cache ca-certificates tzdata && \ adduser -D -u 10001 behavision COPY --from=build /out/behavision-server /usr/local/bin/behavision-server USER behavision EXPOSE 8080 ENTRYPOINT ["/usr/local/bin/behavision-server"]