Files
project-work/worker-toolkit-stocks-in-the-future/explore/.devcontainer/Dockerfile
2026-08-19 10:24:09 +00:00

116 lines
5.3 KiB
Docker

# Explore container for stocks-in-the-future — Rails 8.1 / Ruby 3.4.4, Postgres + Redis.
# rubyforgood/stocks-in-the-future, pinned upstream at 63732df2. Adapted for live-mount:
# repo bind-mounted at /workspace/repo; deps + DB set up by post-create.sh; Postgres +
# Redis brought up by post-start.sh.
#
# Minitest; system specs use Selenium + headless Chrome (the repo's own config already
# passes --no-sandbox + --disable-dev-shm-usage, so no chromium wrapper is needed here).
FROM ruby:3.4.4
RUN apt-get update && apt-get install -y --no-install-recommends \
build-essential pkg-config libpq-dev \
postgresql postgresql-client redis-server \
chromium chromium-driver \
libvips libyaml-dev locales \
python3 \
git sudo curl ca-certificates xz-utils \
&& rm -rf /var/lib/apt/lists/*
# Ferrum/Selenium detect the browser by name; symlink google-chrome → chromium.
RUN ln -sf /usr/bin/chromium /usr/local/bin/google-chrome \
&& ln -sf /usr/bin/chromium /usr/local/bin/google-chrome-stable
# Locale + Postgres collation: rebuild the cluster under en_US.UTF-8 (apt default is
# C.UTF-8 → byte-order; en_US.UTF-8 matches CI's postgres image and avoids locale-
# ordering spec failures).
RUN sed -i 's/^# *en_US.UTF-8 UTF-8/en_US.UTF-8 UTF-8/' /etc/locale.gen \
&& locale-gen \
&& PG_VERSION=$(ls /etc/postgresql) \
&& pg_dropcluster "${PG_VERSION}" main \
&& LANG=en_US.UTF-8 pg_createcluster --locale en_US.UTF-8 "${PG_VERSION}" main
ENV LANG=en_US.UTF-8
ENV LC_ALL=en_US.UTF-8
RUN PG_VERSION=$(ls /etc/postgresql) \
&& printf 'local all all trust\nhost all all 127.0.0.1/32 trust\nhost all all ::1/128 trust\nhost all all 0.0.0.0/0 trust\n' > "/etc/postgresql/${PG_VERSION}/main/pg_hba.conf" \
&& echo "listen_addresses='*'" >> "/etc/postgresql/${PG_VERSION}/main/postgresql.conf"
# config/database.yml.sample specifies no host/user (relies on libpq defaults), so pin
# PGHOST/PGUSER → connect to the local postgres as the `postgres` superuser over TCP
# (trust). REDIS_URL points at the baked-in redis (CI uses db index 1).
ENV PGHOST=localhost
ENV PGUSER=postgres
ENV REDIS_URL=redis://localhost:6379/1
# Node 18 for toolkit tooling (create-snapshot hooks). App is importmap — no Node build.
RUN set -eux; \
arch="$(dpkg --print-architecture)"; \
case "$arch" in amd64) nodearch=x64;; arm64) nodearch=arm64;; *) echo "unsupported arch: $arch" >&2; exit 1;; esac; \
curl -fsSL "https://nodejs.org/dist/v18.20.5/node-v18.20.5-linux-${nodearch}.tar.xz" -o /tmp/node.tar.xz; \
tar -xJf /tmp/node.tar.xz -C /usr/local --strip-components=1; \
rm /tmp/node.tar.xz; node --version
# Match Gemfile.lock "BUNDLED WITH 2.6.7".
RUN gem install bundler -v 2.6.7
USER root
# --- Playwright + Chromium, for driving the app in a real browser -------------
# Self-contained under /opt — the member's own runtime is untouched.
ENV PLAYWRIGHT_BROWSERS_PATH=/opt/ms-playwright
RUN apt-get update -qq \
&& apt-get install -y -qq --no-install-recommends \
xz-utils \
libxcomposite1 \
libxdamage1 \
libxfixes3 \
libxrandr2 \
libasound2 \
libatk1.0-0 \
libatk-bridge2.0-0 \
libatspi2.0-0 \
libcups2 \
libdbus-1-3 \
libgbm1 \
libnspr4 \
libnss3 \
libxkbcommon0 \
libpango-1.0-0 \
libcairo2 \
libxshmfence1 \
libx11-xcb1 \
libxcb-dri3-0 \
libdrm2 \
&& rm -rf /var/lib/apt/lists/*
RUN set -eux; \
arch="$(dpkg --print-architecture)"; \
case "$arch" in amd64) nodearch=x64;; arm64) nodearch=arm64;; *) echo "unsupported arch: $arch" >&2; exit 1;; esac; \
curl -fsSL "https://nodejs.org/dist/v20.19.5/node-v20.19.5-linux-${nodearch}.tar.xz" -o /tmp/pw-node.tar.xz; \
mkdir -p /opt/pw-node; \
tar -xJf /tmp/pw-node.tar.xz -C /opt/pw-node --strip-components=1; \
rm /tmp/pw-node.tar.xz; \
export npm_config_prefix=/opt/pw-node PATH="/opt/pw-node/bin:$PATH"; \
/opt/pw-node/bin/npm install -g playwright@1.56.0; \
test -d /opt/pw-node/lib/node_modules/playwright; \
/opt/pw-node/bin/node /opt/pw-node/lib/node_modules/playwright/cli.js install chromium
# `pw <script.js>` runs Node with `require("playwright")` resolvable (CommonJS).
RUN printf '#!/bin/sh\nNODE_PATH=/opt/pw-node/lib/node_modules exec /opt/pw-node/bin/node "$@"\n' > /usr/local/bin/pw \
&& chmod +x /usr/local/bin/pw
# Fail the build if Chromium cannot start.
RUN printf 'const{chromium}=require("playwright");(async()=>{const b=await chromium.launch();const p=await b.newPage();await p.setContent("<h1 id=t>ok</h1>");if(await p.textContent("#t")!=="ok")throw new Error("bad render");await b.close();console.log("chromium OK");})()\n' > /tmp/pw-check.js \
&& pw /tmp/pw-check.js \
&& rm -f /tmp/pw-check.js
ENV IS_SANDBOX=1
RUN mkdir -p /root/.claude && \
echo '{"permissions":{"deny":["WebFetch","WebSearch"]}}' > /root/.claude/settings.json
WORKDIR /workspace/repo
# Start Postgres + Redis, wait for pg, seed the postgres role password (harmless w/ trust).
RUN printf '#!/bin/bash\nset -e\nservice postgresql start\nservice redis-server start || redis-server --daemonize yes\nuntil pg_isready -h localhost -p 5432 -U postgres >/dev/null 2>&1; do sleep 0.5; done\nexec "$@"\n' > /usr/local/bin/start-services.sh \
&& chmod +x /usr/local/bin/start-services.sh
ENTRYPOINT ["/usr/local/bin/start-services.sh"]
CMD ["sleep", "infinity"]