# Note: Debian Trixie = Debian 13 FROM postgres:17-trixie # Install pg_search from GitHub Releases RUN set -eux; \ apt-get update; \ apt-get install -y --no-install-recommends ca-certificates curl; \ arch="$(dpkg --print-architecture)"; \ case "$arch" in \ amd64) checksum="d47e999cd53e80f6e9bb8c4781d7045def89af245a1c15dc631141b30a04c78a" ;; \ arm64) checksum="b2ef596c14c9ebab640d48cb254f71f5ea1a3b4acfede4154b3499d0f87826a4" ;; \ *) echo "unsupported architecture: $arch" >&2; exit 1 ;; \ esac; \ curl -fsSL -o /tmp/pg_search.deb "https://github.com/paradedb/paradedb/releases/download/v0.25.11/postgresql-17-pg-search_0.25.11-1PARADEDB-trixie_${arch}.deb"; \ echo "${checksum} */tmp/pg_search.deb" | sha256sum --strict --check -; \ apt-get install -y --no-install-recommends /tmp/pg_search.deb; \ apt-get purge -y --auto-remove curl; \ rm /tmp/pg_search.deb; \ apt-get dist-clean # Install Barman Cloud and its dependencies for Azure, Google, and AWS via `pip`, and clean up after the installation to # minimize the size of the image. These are required for enabling Postgres backups in our CloudNativePG deployments. RUN set -eux; \ apt-get update; \ apt-get install -y --no-install-recommends libpq5 python3-pip python3-dev python3-psycopg2; \ rm /usr/lib/python*/EXTERNALLY-MANAGED; \ pip3 install --no-cache-dir 'setuptools==82.0.1' 'barman[cloud,azure,snappy,google]==3.18.0'; \ apt-get remove -y python3-dev python3-pip --purge; \ apt-get autoremove -y; \ apt-get dist-clean; \ find /usr/lib | grep -E "(/__pycache__$|\.pyc$|\.pyo$)" | xargs rm -rf; \ find /usr/local | grep -E "(/__pycache__$|\.pyc$|\.pyo$)" | xargs rm -rf; \ find /var/cache -type f -exec truncate --size 0 {} \;; \ find /var/log -type f -exec truncate --size 0 {} \; # Install core extensions # Use the PGDG archive so these pinned extension versions remain available after newer # versions replace them in the live Debian and PGDG apt repositories. ENV POSTGIS_VERSION_MAJOR=3 RUN set -eux; \ apt-get update; \ echo "deb [ signed-by=/usr/local/share/keyrings/postgres.gpg.asc ] https://apt-archive.postgresql.org/pub/repos/apt trixie-pgdg-archive main" > /etc/apt/sources.list.d/pgdg-archive.list; \ apt-get update; \ apt-get install -y --no-install-recommends \ postgresql-17-pgvector=0.8.6-1.pgdg13+1 \ postgresql-17-cron=1.6.7-3.pgdg13+1 \ postgresql-17-pg-ivm=1.13-1.pgdg13+1 \ postgresql-17-postgis-$POSTGIS_VERSION_MAJOR=3.6.4+dfsg-2.pgdg13+1 \ postgresql-17-postgis-$POSTGIS_VERSION_MAJOR-scripts=3.6.4+dfsg-2.pgdg13+1; \ apt-get dist-clean # The postgresql.conf.sample file is used as a template for the postgresql.conf file, which # does not exist until the first time the container is started. By adding our settings to the # postgresql.conf.sample file, we ensure that our settings are applied onto the postgresql.conf file. # # The `postgres` database is the default database that exists in every Postgres installation. The pg_cron # extension requires a database to store its metadata tables. By using `postgres`, we ensure that it has a # stable, always-available database for its operations, no matter what other databases are created or deleted. RUN set -eux; \ sed -i "s/^#shared_preload_libraries = ''/shared_preload_libraries = 'pg_search,pg_cron,pg_stat_statements'/" /usr/share/postgresql/postgresql.conf.sample; \ grep "shared_preload_libraries = 'pg_search,pg_cron,pg_stat_statements'" /usr/share/postgresql/postgresql.conf.sample; \ echo "cron.database_name = 'postgres'" >> /usr/share/postgresql/postgresql.conf.sample; \ echo "pg_stat_statements.track = 'top'" >> /usr/share/postgresql/postgresql.conf.sample # Copy ParadeDB bootstrap script to install extensions and configure postgresql.conf COPY ./bootstrap.sh /docker-entrypoint-initdb.d/10_bootstrap_paradedb.sh # The upstream `postgres` Docker image comes with its own `entrypoint.sh` script which # starts as `root` and then switches to the `postgres` user after running chown and chmod # on the PostgreSQL data directory. To maintain compatibility with the upstream image and # ensure that the `postgres` user has the correct permissions on the data directory, we let # the upstream `entrypoint.sh` script run as the entrypoint and don't specify a custom user.