mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 08:28:19 +08:00
91 lines
3.2 KiB
Docker
91 lines
3.2 KiB
Docker
# syntax=docker/dockerfile:1.4
|
|
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# CI runner image with all development tools pre-installed
|
|
# Rebuild triggered automatically when mise.toml, mise.lock, tasks, or this file changes
|
|
|
|
FROM nvcr.io/nvidia/base/ubuntu:noble-20251013
|
|
|
|
ARG DOCKER_VERSION=29.5.1
|
|
ARG BUILDX_VERSION=v0.34.0
|
|
ARG NPM_VERSION=11.13.0
|
|
ARG TARGETARCH
|
|
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
ENV MISE_DATA_DIR=/opt/mise
|
|
ENV MISE_CACHE_DIR=/opt/mise/cache
|
|
ENV PATH="/opt/mise/shims:/root/.cargo/bin:/root/.local/bin:$PATH"
|
|
|
|
# Install system dependencies
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
ca-certificates \
|
|
curl \
|
|
git \
|
|
build-essential \
|
|
clang \
|
|
libclang-dev \
|
|
libz3-dev \
|
|
pkg-config \
|
|
libssl-dev \
|
|
musl-tools \
|
|
openssh-client \
|
|
python3 \
|
|
python3-venv \
|
|
cmake \
|
|
socat \
|
|
unzip \
|
|
xz-utils \
|
|
jq \
|
|
rsync \
|
|
zstd \
|
|
&& apt-get install -y --only-upgrade gpgv python3 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install Docker CLI and buildx plugin used by CI jobs
|
|
RUN case "$TARGETARCH" in \
|
|
amd64) docker_arch=x86_64; buildx_arch=amd64 ;; \
|
|
arm64) docker_arch=aarch64; buildx_arch=arm64 ;; \
|
|
*) echo "Unsupported TARGETARCH: $TARGETARCH"; exit 1 ;; \
|
|
esac \
|
|
&& curl -fsSL "https://download.docker.com/linux/static/stable/${docker_arch}/docker-${DOCKER_VERSION}.tgz" \
|
|
| tar xz --strip-components=1 -C /usr/local/bin docker/docker \
|
|
&& mkdir -p /usr/local/lib/docker/cli-plugins \
|
|
&& curl -fsSL "https://github.com/docker/buildx/releases/download/${BUILDX_VERSION}/buildx-${BUILDX_VERSION}.linux-${buildx_arch}" \
|
|
-o /usr/local/lib/docker/cli-plugins/docker-buildx \
|
|
&& chmod +x /usr/local/lib/docker/cli-plugins/docker-buildx
|
|
|
|
# Install GitHub CLI used by install.sh and CI jobs
|
|
ARG GH_VERSION=2.92.0
|
|
RUN case "$TARGETARCH" in \
|
|
amd64) gh_arch=amd64 ;; \
|
|
arm64) gh_arch=arm64 ;; \
|
|
*) echo "Unsupported TARGETARCH: $TARGETARCH"; exit 1 ;; \
|
|
esac \
|
|
&& curl -fsSL "https://github.com/cli/cli/releases/download/v${GH_VERSION}/gh_${GH_VERSION}_linux_${gh_arch}.tar.gz" \
|
|
| tar xz --strip-components=2 -C /usr/local/bin "gh_${GH_VERSION}_linux_${gh_arch}/bin/gh"
|
|
|
|
# Install mise (NOTE: keep this version in sync with mise.toml)
|
|
ARG MISE_VERSION=v2026.9.9
|
|
RUN curl https://mise.run | MISE_VERSION=$MISE_VERSION sh
|
|
|
|
# Copy mise.toml and task includes, then install all tools via mise
|
|
COPY mise.toml /opt/mise/mise.toml
|
|
COPY mise.lock /opt/mise/mise.lock
|
|
COPY tasks/ /opt/mise/tasks/
|
|
WORKDIR /opt/mise
|
|
RUN --mount=type=secret,id=MISE_GITHUB_TOKEN \
|
|
export MISE_GITHUB_TOKEN="$(cat /run/secrets/MISE_GITHUB_TOKEN 2>/dev/null || true)" && \
|
|
mise trust /opt/mise/mise.toml && \
|
|
env -u RUSTC_WRAPPER mise install --locked && \
|
|
mise reshim && \
|
|
npm install -g "npm@${NPM_VERSION}" && \
|
|
mise reshim && \
|
|
(/root/.cargo/bin/rustup component remove rust-docs || true) && \
|
|
rm -rf /root/.rustup/toolchains/*/share/doc /root/.rustup/toolchains/*/share/man && \
|
|
helm plugin install https://github.com/helm-unittest/helm-unittest --verify=false
|
|
|
|
# Set working directory for CI jobs
|
|
WORKDIR /builds
|