# syntax=docker/dockerfile:1.4 # SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. # SPDX-License-Identifier: Apache-2.0 # CI runner image with all development tools pre-installed # Rebuild triggered automatically when mise.toml, mise.lock, tasks, or this file changes FROM nvcr.io/nvidia/base/ubuntu:noble-20251013 ARG DOCKER_VERSION=29.5.1 ARG BUILDX_VERSION=v0.34.0 ARG NPM_VERSION=11.13.0 ARG TARGETARCH ENV DEBIAN_FRONTEND=noninteractive ENV MISE_DATA_DIR=/opt/mise ENV MISE_CACHE_DIR=/opt/mise/cache ENV PATH="/opt/mise/shims:/root/.cargo/bin:/root/.local/bin:$PATH" # Install system dependencies RUN apt-get update && apt-get install -y --no-install-recommends \ ca-certificates \ curl \ git \ build-essential \ clang \ libclang-dev \ libz3-dev \ pkg-config \ libssl-dev \ musl-tools \ openssh-client \ python3 \ python3-venv \ cmake \ socat \ unzip \ xz-utils \ jq \ rsync \ zstd \ && apt-get install -y --only-upgrade gpgv python3 \ && rm -rf /var/lib/apt/lists/* # Install Docker CLI and buildx plugin used by CI jobs RUN case "$TARGETARCH" in \ amd64) docker_arch=x86_64; buildx_arch=amd64 ;; \ arm64) docker_arch=aarch64; buildx_arch=arm64 ;; \ *) echo "Unsupported TARGETARCH: $TARGETARCH"; exit 1 ;; \ esac \ && curl -fsSL "https://download.docker.com/linux/static/stable/${docker_arch}/docker-${DOCKER_VERSION}.tgz" \ | tar xz --strip-components=1 -C /usr/local/bin docker/docker \ && mkdir -p /usr/local/lib/docker/cli-plugins \ && curl -fsSL "https://github.com/docker/buildx/releases/download/${BUILDX_VERSION}/buildx-${BUILDX_VERSION}.linux-${buildx_arch}" \ -o /usr/local/lib/docker/cli-plugins/docker-buildx \ && chmod +x /usr/local/lib/docker/cli-plugins/docker-buildx # Install GitHub CLI used by install.sh and CI jobs ARG GH_VERSION=2.92.0 RUN case "$TARGETARCH" in \ amd64) gh_arch=amd64 ;; \ arm64) gh_arch=arm64 ;; \ *) echo "Unsupported TARGETARCH: $TARGETARCH"; exit 1 ;; \ esac \ && curl -fsSL "https://github.com/cli/cli/releases/download/v${GH_VERSION}/gh_${GH_VERSION}_linux_${gh_arch}.tar.gz" \ | tar xz --strip-components=2 -C /usr/local/bin "gh_${GH_VERSION}_linux_${gh_arch}/bin/gh" # Install mise (NOTE: keep this version in sync with mise.toml) ARG MISE_VERSION=v2026.9.9 RUN curl https://mise.run | MISE_VERSION=$MISE_VERSION sh # Copy mise.toml and task includes, then install all tools via mise COPY mise.toml /opt/mise/mise.toml COPY mise.lock /opt/mise/mise.lock COPY tasks/ /opt/mise/tasks/ WORKDIR /opt/mise RUN --mount=type=secret,id=MISE_GITHUB_TOKEN \ export MISE_GITHUB_TOKEN="$(cat /run/secrets/MISE_GITHUB_TOKEN 2>/dev/null || true)" && \ mise trust /opt/mise/mise.toml && \ env -u RUSTC_WRAPPER mise install --locked && \ mise reshim && \ npm install -g "npm@${NPM_VERSION}" && \ mise reshim && \ (/root/.cargo/bin/rustup component remove rust-docs || true) && \ rm -rf /root/.rustup/toolchains/*/share/doc /root/.rustup/toolchains/*/share/man && \ helm plugin install https://github.com/helm-unittest/helm-unittest --verify=false # Set working directory for CI jobs WORKDIR /builds