Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
164 lines (137 loc) · 7.19 KB
/
Copy pathDockerfile
File metadata and controls
164 lines (137 loc) · 7.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
ARG BASE_IMAGE=ubuntu:noble
## Commit a19e364 corresponds to Conan package nmos-cpp/cci.20260812
ARG NMOS_CPP_VERSION=a19e3648ecfd620715b0f0fe3f184c6b7f26a996
## Tip of master including NMOS Bridge, IS-08 channel mapping edit, and NCP WebSockets
ARG NMOS_JS_VERSION=182b3722cc9de04b2cb5ba60d1a09d5cf733bf30
############################################################
# Stage 1 — build nmos-cpp, certs, and assemble /home
############################################################
FROM ${BASE_IMAGE} AS stage1-build
LABEL maintainer="rhastie@nvidia.com"
ARG makemt
ARG NMOS_CPP_VERSION
ARG CMAKE_BUILD_TYPE=Release
ENV APT_KEY_DONT_WARN_ON_DANGEROUS_USAGE=DontWarn
RUN apt-get update && export DEBIAN_FRONTEND=noninteractive && apt-get install -y --no-install-recommends \
g++ build-essential \
openssl libssl-dev git wget gnupg curl ca-certificates nano \
python3 python3-venv rdma-core && \
rm -rf /var/lib/apt/lists/* && \
apt-get clean -y --no-install-recommends && \
apt-get autoclean -y --no-install-recommends
## Install CMake and Conan in a venv (Noble blocks system-wide pip — PEP 668)
RUN python3 -m venv /opt/venv
ENV PATH=/opt/venv/bin:$PATH
RUN pip install --no-cache-dir "cmake~=3.31" "conan~=2.29"
## Get Certificates and scripts from AMWA-TV/nmos-testing
RUN cd /home && mkdir certs && git config --global http.sslVerify false && \
git clone https://github.com/AMWA-TV/nmos-testing.git && \
mv /home/nmos-testing/test_data/BCP00301/ca/* /home/certs && \
rm -rf /home/nmos-testing
## Get source for Sony nmos-cpp
RUN cd /home/ && curl --output - -s -k https://codeload.github.com/sony/nmos-cpp/tar.gz/${NMOS_CPP_VERSION} | tar zxvf - -C . && \
mv ./nmos-cpp-${NMOS_CPP_VERSION} ./nmos-cpp
## You should use either Avahi or Apple mDNS - DO NOT use both
##
## mDNSResponder 878.260.1 Build and install
RUN cd /home/ && curl --output - -s -k https://codeload.github.com/apple-oss-distributions/mDNSResponder/tar.gz/mDNSResponder-878.260.1 | tar zxvf - -C . && \
mv ./mDNSResponder-mDNSResponder-878.260.1 ./mDNSResponder && \
patch -d mDNSResponder/ -p1 <nmos-cpp/Development/third_party/mDNSResponder/unicast.patch && \
patch -d mDNSResponder/ -p1 <nmos-cpp/Development/third_party/mDNSResponder/permit-over-long-service-types.patch && \
patch -d mDNSResponder/ -p1 <nmos-cpp/Development/third_party/mDNSResponder/poll-rather-than-select.patch && \
cd /home/mDNSResponder/mDNSPosix && HAVE_IPV6=0 make os=linux && make os=linux install
## Build Sony nmos-cpp from sources
ARG CMAKE_BUILD_TYPE
RUN conan profile detect --force \
&& cmake -S /home/nmos-cpp/Development -B /home/nmos-cpp/Development/build \
-G "Unix Makefiles" \
-DCMAKE_PROJECT_TOP_LEVEL_INCLUDES=third_party/cmake/conan_provider.cmake \
-DCMAKE_BUILD_TYPE=${CMAKE_BUILD_TYPE} \
-DNMOS_CPP_USE_AVAHI=OFF \
-DNMOS_CPP_BUILD_EXAMPLES=ON \
-DNMOS_CPP_BUILD_TESTS=OFF \
&& cmake --build /home/nmos-cpp/Development/build \
--target nmos-cpp-registry nmos-cpp-node \
--parallel ${makemt:-$(nproc)}
## Generate Example Certificates and position into correct locations
RUN cd /home/certs && mkdir run-certs && ./generateCerts registration1 nmos.tv query1.nmos.tv && \
cd /home/certs/certs && \
cp ca.cert.pem /home/certs/run-certs/ca.cert.pem && \
cd /home/certs/intermediate/certs && \
mv ecdsa.registration1.nmos.tv.cert.chain.pem /home/certs/run-certs/ecdsa.cert.chain.pem && \
mv rsa.registration1.nmos.tv.cert.chain.pem /home/certs/run-certs/rsa.cert.chain.pem && \
cd /home/certs/intermediate/private && \
mv ecdsa.registration1.nmos.tv.key.pem /home/certs/run-certs/ecdsa.key.pem && \
mv rsa.registration1.nmos.tv.key.pem /home/certs/run-certs/rsa.key.pem && \
cp dhparam.pem /home/certs/run-certs/dhparam.pem
## Create relevant configuration files for Sony Registry and Node
RUN cd /home/ && mkdir example-conf && mkdir admin
ADD example-conf /home/example-conf
## Move executables, libraries and clean up container as much as possible
RUN cd /home/nmos-cpp/Development/build && \
cp nmos-cpp-node nmos-cpp-registry /home && \
cd /home && rm -rf .git nmos-cpp
############################################################
# Stage 2 — build the nmos-js browser UI (static files)
############################################################
FROM node:20-bookworm-slim AS js-build
ARG NMOS_JS_VERSION
# Do not fail the build on lint warnings, and skip source maps to save space.
ENV CI=false
ENV GENERATE_SOURCEMAP=false
RUN apt-get update && apt-get install -y --no-install-recommends \
curl ca-certificates patch \
&& rm -rf /var/lib/apt/lists/*
## Get source for Sony nmos-js
WORKDIR /home
RUN curl --output - -fsSL https://codeload.github.com/sony/nmos-js/tar.gz/${NMOS_JS_VERSION} | tar zx -C . \
&& mv ./nmos-js-${NMOS_JS_VERSION} ./nmos-js
## Custom branding
COPY NVIDIA_Logo_H_ForScreen_ForLightBG.png nmos-js.patch /home/nmos-js/Development/src/assets/
RUN mv /home/nmos-js/Development/src/assets/nmos-js.patch /home/nmos-js.patch \
&& patch -p0 < /home/nmos-js.patch \
&& rm /home/nmos-js/Development/src/assets/sea-lion.png \
&& rm /home/nmos-js.patch
## Build and install nmos-js and co-located IS-12 browser under /admin/
WORKDIR /home/nmos-js/Development
RUN corepack enable \
&& yarn install --network-timeout 1000000 \
&& yarn build \
&& mkdir -p /admin && cp -rf build/* /admin/
WORKDIR /home/nmos-js/is12-client
RUN yarn install --network-timeout 1000000 \
&& PUBLIC_URL=/admin/is12-client yarn build \
&& mkdir -p /admin/is12-client && cp -rf build/* /admin/is12-client/
############################################################
# Stage 3 — slim runtime image
############################################################
## Re-build container for optimised runtime environment using clean base image
FROM ${BASE_IMAGE}
##Copy required files from build container
COPY --from=stage1-build /home /home
COPY --from=js-build /admin /home/admin
##Update container with latest patches and needed packages
RUN apt-get update && export DEBIAN_FRONTEND=noninteractive && apt-get install -y --no-install-recommends \
openssl make nano curl jq rdma-core mosquitto && \
# Avahi: dbus avahi-daemon libavahi-compat-libdnssd-dev libnss-mdns AND NOT make \
cd /home/mDNSResponder/mDNSPosix && make os=linux install && \
cd /home && rm -rf /home/mDNSResponder /etc/nsswitch.conf.pre-mdns && \
apt-get remove --purge -y make && \
apt-get autoremove -y && \
apt-get clean -y --no-install-recommends && \
apt-get autoclean -y --no-install-recommends && \
rm -rf /var/lib/apt/lists/* && \
rm -rf /usr/share/doc/ && rm -rf /usr/share/man/ && rm -rf /usr/share/locale/ && \
rm -rf /usr/local/share/man/* && rm -rf /usr/local/share/.cache/*
##Copy entrypoint.sh script and master config to image
COPY entrypoint.sh container-config registry.json node.json /home/
##Set script to executable
RUN chmod +x /home/entrypoint.sh
##Set default config variable to run registry (FALSE) or node (TRUE)
ARG runnode=FALSE
ENV RUN_NODE=$runnode
##Expose correct default ports to allow quick publishing
EXPOSE 8010 8011 11000 11001 1883 5353/udp
WORKDIR /home/
ENTRYPOINT ["/home/entrypoint.sh"]
#CMD []