2924cbb63d
ci/woodpecker/pr/build Pipeline was successful
- pin UPSTREAM_REF to the v12.0 rebase commit - move publish to dotnet SDK 10.0 and the runtime to aspnet:10.0 - pin jellyfin-web to 12.0+deb12 - bake LDAP Authentication 24.0.0.0 (targetAbi 12.0.0.0) - build PR images with the CA-baked buildx plugin
94 lines
4.6 KiB
Docker
94 lines
4.6 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Runtime-only image for the jellyfin-ha fork.
|
|
#
|
|
# The .NET publish step runs on the CI host (see .woodpecker/*.yaml) and drops
|
|
# its output into ./publish-output, which is COPYed in below. This file is a
|
|
# vendored copy of upstream's Dockerfile.runtime so we control the pinned
|
|
# jellyfin-web version and base image; bump alongside UPSTREAM_REF.
|
|
|
|
# ── Web client stage ──────────────────────────────────────────────────────────
|
|
# Install jellyfin-web via the official Jellyfin apt repo (prebuilt, no npm).
|
|
# Web assets land at /usr/share/jellyfin/web/.
|
|
FROM --platform=linux/amd64 debian:bookworm-slim AS webclient
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends curl gnupg ca-certificates \
|
|
&& curl -fsSL https://repo.jellyfin.org/jellyfin_team.gpg.key \
|
|
| gpg --dearmor -o /usr/share/keyrings/jellyfin.gpg \
|
|
&& echo "deb [arch=amd64 signed-by=/usr/share/keyrings/jellyfin.gpg] https://repo.jellyfin.org/debian bookworm main" \
|
|
> /etc/apt/sources.list.d/jellyfin.list \
|
|
&& apt-get update \
|
|
&& apt-get install -y --no-install-recommends "jellyfin-web=12.0+deb12" \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# ── Plugin stage ──────────────────────────────────────────────────────────────
|
|
# Download and verify the auth plugins, unpacked into versioned dirs baked into
|
|
# the image and synced into /config/plugins at start (docker-entrypoint.sh).
|
|
# Versions are the newest each plugin publishes whose targetAbi <= the pinned
|
|
# Jellyfin server version (12.0.0):
|
|
# LDAP Authentication 24.0.0.0 targetAbi 12.0.0.0
|
|
# SSO Authentication 4.0.0.4 targetAbi 10.11.0.0 (newest release; loads on 12.0)
|
|
# sha256 pins make each fetch reproducible.
|
|
FROM --platform=linux/amd64 debian:bookworm-slim AS plugins
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends curl ca-certificates unzip \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_24.0.0.0.zip
|
|
ARG LDAP_SHA256=3be1f9d6a6ce9ea375e556dd30136d178a8dbe35cbe866d30d3451dc3ff7e804
|
|
# LDAP is served through artifactapi remote. SSO is served through the artifactapi
|
|
# github proxy, which the CI build network can reach (github is not directly reachable).
|
|
ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/9p4/jellyfin-plugin-sso/releases/download/v4.0.0.4/sso-authentication_4.0.0.4.zip
|
|
ARG SSO_SHA256=c09f16ba31059a434ddd7f811e4f9608d4b4c4514cc80a5bf1ca33bee61e1107
|
|
|
|
WORKDIR /plugins
|
|
RUN set -eu; \
|
|
curl -fsSL "$LDAP_URL" -o ldap.zip; \
|
|
echo "$LDAP_SHA256 ldap.zip" | sha256sum -c -; \
|
|
mkdir -p "LDAP Authentication_24.0.0.0"; \
|
|
unzip -oq ldap.zip -d "LDAP Authentication_24.0.0.0"; \
|
|
curl -fsSL "$SSO_URL" -o sso.zip; \
|
|
echo "$SSO_SHA256 sso.zip" | sha256sum -c -; \
|
|
mkdir -p "SSO Authentication_4.0.0.4"; \
|
|
unzip -oq sso.zip -d "SSO Authentication_4.0.0.4"; \
|
|
rm -f ldap.zip sso.zip
|
|
|
|
# ── Runtime stage ─────────────────────────────────────────────────────────────
|
|
# .NET 10 runtime: matches the SDK 10.0 publish step (framework-dependent) and the
|
|
# fork's net10.0 TFM, so the app's required Microsoft.NETCore.App 10.0 is present.
|
|
# Keep in lockstep with the `mcr.microsoft.com/dotnet/sdk` major in .woodpecker/*.yaml.
|
|
FROM --platform=linux/amd64 mcr.microsoft.com/dotnet/aspnet:10.0
|
|
|
|
# FFmpeg and the native deps required by SkiaSharp and fontconfig.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends \
|
|
ffmpeg \
|
|
fontconfig \
|
|
libfontconfig1 \
|
|
libfreetype6 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /jellyfin
|
|
|
|
# Pre-built publish output produced by `dotnet publish` on the CI host.
|
|
COPY publish-output/ .
|
|
# jellyfin-web client assets from the webclient stage.
|
|
COPY --from=webclient /usr/share/jellyfin/web ./jellyfin-web/
|
|
# Baked auth plugins; docker-entrypoint.sh syncs these into /config/plugins.
|
|
COPY --from=plugins /plugins /usr/share/jellyfin/plugins-baked
|
|
COPY --chmod=0755 docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
|
|
|
# Jellyfin default ports
|
|
EXPOSE 8096
|
|
EXPOSE 8920
|
|
|
|
# Data / config volumes
|
|
VOLUME ["/config", "/cache", "/media"]
|
|
|
|
ENV JELLYFIN_DATA_DIR=/config \
|
|
JELLYFIN_CACHE_DIR=/cache \
|
|
JELLYFIN_LOG_DIR=/config/log
|
|
|
|
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
|