commit daa240f5c5cb12d34d927d35dfe9c74c4500420f Author: Alex Maldonado Date: Fri Aug 7 13:39:56 2026 -0400 Initial commit diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..d57ee22 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,77 @@ +# syntax=docker/dockerfile:1 +# +# Gitea Actions job-container image for building Rust projects with pixi. +# +# The job never downloads the Rust toolchain: the compiler, C toolchain, and +# pkg-config are baked into pixi's package cache at build time, so `pixi install` +# in a job only links them into the environment instead of fetching them. sccache +# is included so unchanged dependencies are served from a cache instead of being +# recompiled every run. + +FROM node:26-trixie-slim@sha256:a1d9d671994fc2d26e297ac56b4b1522a8bc7fa71c43b14cd1b1fe6c5116f7dc + +# node is here because Gitea's JavaScript actions (actions/checkout and friends) +# need it. git and ca-certificates are for checkout; curl is for the release API +# calls in the workflows. The C compiler is not installed here: pixi brings it. +RUN apt-get update \ + && apt-get install -y --no-install-recommends \ + git ca-certificates curl \ + && rm -rf /var/lib/apt/lists/* + +COPY --from=ghcr.io/prefix-dev/pixi:0.76.1 /usr/local/bin/pixi /usr/local/bin/pixi + +# --- Bake the Rust toolchain into pixi's package cache --- +# PIXI_CACHE_DIR is the shared store of downloaded conda packages. Point it at a +# stable path and pre-fill it by installing a throwaway environment that pins the +# same toolchain your projects use. At job time, pixi finds these packages +# already unpacked here and hardlinks them into .pixi/envs with no download. Keep +# RUST_VERSION in step with the projects' pixi.toml; rebuild the image when it +# moves. +ENV PIXI_CACHE_DIR=/opt/pixi/cache +ARG RUST_VERSION=">=1.96.0,<1.97" +RUN < pixi.toml <- + -v pixi-cache:/opt/pixi/cache + -v cargo-home:/opt/cargo + -v sccache:/opt/sccache +``` + +Docker fills an empty named volume from the image's contents at that path the first time it is used, so the baked toolchain is present on the first job and the volume holds any later changes. +That is runner configuration, not part of this image. \ No newline at end of file