# syntax=docker/dockerfile:1 # Runtime-only image for the jellyfin-ha fork. # # The .NET publish step runs on the CI host (see .woodpecker/*.yaml) and drops # its output into ./publish-output, which is COPYed in below. This file is a # vendored copy of upstream's Dockerfile.runtime so we control the pinned # jellyfin-web version and base image; bump alongside UPSTREAM_REF. # ── Web client stage ────────────────────────────────────────────────────────── # Install jellyfin-web via the official Jellyfin apt repo (prebuilt, no npm). # Web assets land at /usr/share/jellyfin/web/. FROM --platform=linux/amd64 debian:bookworm-slim AS webclient RUN apt-get update \ && apt-get install -y --no-install-recommends curl gnupg ca-certificates \ && curl -fsSL https://repo.jellyfin.org/jellyfin_team.gpg.key \ | gpg --dearmor -o /usr/share/keyrings/jellyfin.gpg \ && echo "deb [arch=amd64 signed-by=/usr/share/keyrings/jellyfin.gpg] https://repo.jellyfin.org/debian bookworm main" \ > /etc/apt/sources.list.d/jellyfin.list \ && apt-get update \ && apt-get install -y --no-install-recommends "jellyfin-web=12.0+deb12" \ && rm -rf /var/lib/apt/lists/* # ── Plugin stage ────────────────────────────────────────────────────────────── # Download and verify the auth plugins, unpacked into versioned dirs baked into # the image and synced into /config/plugins at start (docker-entrypoint.sh). # Versions are the newest each plugin publishes whose targetAbi <= the pinned # Jellyfin server version (12.0.0): # LDAP Authentication 24.0.0.0 targetAbi 12.0.0.0 # SSO Authentication 5.0.0.0 targetAbi 12.0.0.0 # sha256 pins make each fetch reproducible. FROM --platform=linux/amd64 debian:bookworm-slim AS plugins RUN apt-get update \ && apt-get install -y --no-install-recommends curl ca-certificates unzip \ && rm -rf /var/lib/apt/lists/* ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_24.0.0.0.zip ARG LDAP_SHA256=3be1f9d6a6ce9ea375e556dd30136d178a8dbe35cbe866d30d3451dc3ff7e804 # Both are served through artifactapi remotes over http: this stage's base image # trusts only public CAs and artifactapi presents an internal-CA certificate, so # https here fails to verify. The sha256 pins below supply the integrity guarantee. # SSO is the in-house unkin fork (valkey-backed OAuth state, shared across replicas). ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v2/remotes/jellyfin-plugins/files/unkin/jellyfin-plugin-sso/5.0.0.0/sso-authentication_5.0.0.0.zip ARG SSO_SHA256=7e5f09cc4c81dce35edca650d74ed0680f425ca65c6221bb75456de9b8557e14 WORKDIR /plugins RUN set -eu; \ curl -fsSL "$LDAP_URL" -o ldap.zip; \ echo "$LDAP_SHA256 ldap.zip" | sha256sum -c -; \ mkdir -p "LDAP Authentication_24.0.0.0"; \ unzip -oq ldap.zip -d "LDAP Authentication_24.0.0.0"; \ curl -fsSL "$SSO_URL" -o sso.zip; \ echo "$SSO_SHA256 sso.zip" | sha256sum -c -; \ mkdir -p "SSO Authentication_5.0.0.0"; \ unzip -oq sso.zip -d "SSO Authentication_5.0.0.0"; \ rm -f ldap.zip sso.zip # ── Runtime stage ───────────────────────────────────────────────────────────── # .NET 10 runtime: matches the SDK 10.0 publish step (framework-dependent) and the # fork's net10.0 TFM, so the app's required Microsoft.NETCore.App 10.0 is present. # Keep in lockstep with the `mcr.microsoft.com/dotnet/sdk` major in .woodpecker/*.yaml. FROM --platform=linux/amd64 mcr.microsoft.com/dotnet/aspnet:10.0 # FFmpeg and the native deps required by SkiaSharp and fontconfig. RUN apt-get update \ && apt-get install -y --no-install-recommends \ ffmpeg \ fontconfig \ libfontconfig1 \ libfreetype6 \ && rm -rf /var/lib/apt/lists/* WORKDIR /jellyfin # Pre-built publish output produced by `dotnet publish` on the CI host. COPY publish-output/ . # jellyfin-web client assets from the webclient stage. COPY --from=webclient /usr/share/jellyfin/web ./jellyfin-web/ # Baked auth plugins; docker-entrypoint.sh syncs these into /config/plugins. COPY --from=plugins /plugins /usr/share/jellyfin/plugins-baked COPY --chmod=0755 docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh # Jellyfin default ports EXPOSE 8096 EXPOSE 8920 # Data / config volumes VOLUME ["/config", "/cache", "/media"] ENV JELLYFIN_DATA_DIR=/config \ JELLYFIN_CACHE_DIR=/cache \ JELLYFIN_LOG_DIR=/config/log ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]