From 91f1f413670b974697240d72d333282266990aa0 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 10 Jun 2026 08:35:39 +0000 Subject: [PATCH 1/3] build(docker): drop libpq runtime dep and postgresql-dev build dep sqlx's postgres driver implements the wire protocol in pure Rust and TLS goes through rustls, so libpq is never linked. Confirmed via Cargo.lock: no pq-sys, native-tls, or openssl-sys in the dependency tree. Removing postgresql-dev from the build base and libpq from the runtime image shrinks the final image by ~3 MB and removes a C library from the attack/patch surface. perl/make/gcc/musl-dev are kept for the C builds of aws-lc-sys. https://claude.ai/code/session_01GpprjxjtXFYLfXNkoKnHuL --- Dockerfile | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 59dc48e2..e50b8107 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,7 +1,10 @@ # ─── Stage 1: Shared build base (avoids duplicate apk install) ──────────────── FROM rust:1.94.1-alpine3.23 AS base +# sqlx's postgres driver speaks the wire protocol in pure Rust (no pq-sys in +# Cargo.lock) and TLS goes through rustls, so libpq headers are never needed at +# build time. perl/make/gcc/musl-dev remain for the C builds of aws-lc-sys. RUN apk --no-cache upgrade && \ - apk add --no-cache musl-dev pkgconfig postgresql-dev gcc perl make + apk add --no-cache musl-dev pkgconfig gcc perl make # ─── Stage 2: Cache dependencies ───────────────────────────────────────────── FROM base AS cacher @@ -49,9 +52,10 @@ LABEL org.opencontainers.image.title="OxiCloud" \ org.opencontainers.image.licenses="MIT" # Install only necessary runtime dependencies and update packages -# su-exec is needed by the entrypoint to drop privileges after fixing volume permissions +# su-exec is needed by the entrypoint to drop privileges after fixing volume permissions. +# No libpq: the pure-Rust sqlx postgres driver never links it. RUN apk --no-cache upgrade && \ - apk add --no-cache libgcc ca-certificates libpq tzdata su-exec && \ + apk add --no-cache libgcc ca-certificates tzdata su-exec && \ addgroup -g 1001 -S oxicloud && \ adduser -u 1001 -S oxicloud -G oxicloud From 9e3d990bd327a557f3babfa34e5946ec8bd1ebeb Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 10 Jun 2026 08:38:24 +0000 Subject: [PATCH 2/3] build(docker): trim build context, fix docs/ ignore typo The .dockerignore excluded a non-existent doc/ directory (the real one is docs/) and did not exclude tests/, images/, charts/, or tools/. None of these are COPYed by the Dockerfile, yet ~24 MB of them were sent to the daemon as build context on every build. Fix the typo and exclude the unused asset/tooling directories so the context stays minimal. https://claude.ai/code/session_01GpprjxjtXFYLfXNkoKnHuL --- .dockerignore | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/.dockerignore b/.dockerignore index 3b855bb0..eb838161 100644 --- a/.dockerignore +++ b/.dockerignore @@ -21,11 +21,19 @@ rootless-compose.yml storage/ # Documentation -doc/ +docs/ *.md LICENSE CODEOWNERS +# Project assets and tooling not needed by the build +# (the Dockerfile only COPYs src, static, migrations, templates, build.rs, +# Cargo.*, and entrypoint.sh; everything else is dead weight in the context) +images/ +charts/ +tools/ +tests/ + # Miscellaneous .github/ .env From d32ec359cd9bf6988e22bf5f635f7a29d4e67b0b Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 10 Jun 2026 08:41:14 +0000 Subject: [PATCH 3/3] perf(docker): skip recursive chown when volume is already owned The entrypoint ran "chown -R" on the storage volume on every container start. Storage is a content-addressable blob store that can hold millions of objects, so a blind recursive chown re-stats and rewrites the inode of every blob on each boot, adding minutes of startup time and saturating the disk on spinning media. Guard the chown behind a top-level ownership check: only recurse when the directory root is not already owned by the oxicloud user. The first boot fixes a freshly mounted (root-owned) volume; every later boot is a no-op. The same guard is applied to the static dir, factored into a shared helper. The target UID is resolved via "id -u oxicloud" instead of hardcoding 1001. https://claude.ai/code/session_01GpprjxjtXFYLfXNkoKnHuL --- entrypoint.sh | 26 +++++++++++++++++++------- 1 file changed, 19 insertions(+), 7 deletions(-) diff --git a/entrypoint.sh b/entrypoint.sh index 1b757c10..f0490dae 100755 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -9,14 +9,26 @@ set -e STORAGE_DIR="/app/storage" STATIC_DIR="/app/static" -# Ensure the storage directory exists and is writable by oxicloud -if [ -d "$STORAGE_DIR" ] && [ "$(id -u)" -eq 0 ]; then - chown -R oxicloud:oxicloud "$STORAGE_DIR" -fi +# Recursively chown DIR to the oxicloud user, but only when its top-level +# entry is not already owned by that user. The storage volume is a +# content-addressable blob store that can hold millions of objects; a blind +# "chown -R" on every boot would re-stat and rewrite the inode of every blob, +# turning startup into minutes of disk I/O. Checking the root entry is the +# cheap idempotent guard: the first boot fixes a freshly mounted (root-owned) +# volume, and every later boot is a no-op. +ensure_owned() { + dir="$1" + if [ -d "$dir" ] && [ "$(stat -c %u "$dir")" != "$OXI_UID" ]; then + chown -R oxicloud:oxicloud "$dir" + fi +} -# Ensure static directory is readable -if [ -d "$STATIC_DIR" ] && [ "$(id -u)" -eq 0 ]; then - chown -R oxicloud:oxicloud "$STATIC_DIR" +# Only root can chown; when started unprivileged the volume permissions are +# assumed to be correct already. +if [ "$(id -u)" -eq 0 ]; then + OXI_UID="$(id -u oxicloud)" + ensure_owned "$STORAGE_DIR" + ensure_owned "$STATIC_DIR" fi # Drop privileges and exec the main binary (or whatever was passed as CMD)