# RESOURCE RECOMMENDATIONS: # - Minimum 2GB memory limit for compilation # - Minimum 1 CPU core for compilation # # Use in Kubernetes with resource limits: # resources: # requests: # memory: "2Gi" # cpu: "1000m" # limits: # memory: "4Gi" # cpu: "2000m" FROM rust:1.97-slim-trixie AS builder # pipefail for the piped build command below (hadolint DL4006). SHELL ["/bin/bash", "-o", "pipefail", "-c"] # Install build dependencies. None of these packages or the Rust toolchain are # copied into the runtime image below. RUN apt-get update && apt-get upgrade -y && apt-get install -y --no-install-recommends \ build-essential \ lld \ pkg-config \ libpq-dev \ libssl-dev \ libpng-dev \ libjpeg-dev \ libfontconfig1-dev \ curl \ postgresql-client \ && rm -rf /var/lib/apt/lists/* # Set working directory WORKDIR /home/app # Copy the source needed to compile Stressgres. COPY . . # Fetch dependencies before the offline Cargo build. Sancov flags are scoped to the host triple # (resolved here, not hardcoded, so it also builds on arm64 CI) via # CARGO_TARGET__RUSTFLAGS + --target, keeping them off host build scripts. Coverage shim # comes from `--features dst`; its build script needs curl + a C toolchain. # See https://antithesis.com/docs/reference/sdk/rust/instrumentation RUN cargo fetch --manifest-path /home/app/Cargo.toml && \ TARGET="$(rustc -vV | sed -n 's/^host: //p')" && \ env "CARGO_TARGET_$(echo "$TARGET" | tr 'a-z-' 'A-Z_')_RUSTFLAGS=-Ccodegen-units=1 -Cpasses=sancov-module -Cllvm-args=-sanitizer-coverage-level=3 -Cllvm-args=-sanitizer-coverage-trace-pc-guard -Clink-args=-Wl,--build-id" \ cargo build --offline --profile dst --target "$TARGET" \ --manifest-path /home/app/Cargo.toml -p stressgres --features dst && \ cp "/home/app/target/$TARGET/dst/stressgres" /tmp/stressgres && \ cp /usr/lib/postgresql/17/bin/psql /tmp/psql # Keep compilers, development headers, Cargo sources, and build intermediates # out of the image that actually runs. Besides making the image much smaller, # this avoids reporting build-only packages such as linux-libc-dev as runtime # vulnerabilities. FROM debian:trixie-slim AS runtime # Upgrade the runtime packages so a rebuild picks up all available Debian # security fixes. psql is used by the Antithesis setup/verification scripts; # util-linux provides flock for the recovery-liveness script. RUN apt-get update && apt-get upgrade -y && apt-get install -y --no-install-recommends \ bash \ ca-certificates \ libfontconfig1 \ libpq5 \ libreadline8t64 \ libssl3t64 \ util-linux \ && rm -rf /var/lib/apt/lists/* RUN useradd --create-home --shell /bin/bash app WORKDIR /home/app # Preserve the paths used by the public Docker examples and Antithesis while copying only runtime # inputs. The unstripped binary under /symbols lets Antithesis symbolize instrumented crashes. COPY --chown=app:app --from=builder /tmp/stressgres /symbols/stressgres # Copy the native client without postgresql-client-common and its unused Perl runtime. Because the # Debian package database is not copied with it, package-based scanners may not inventory psql. COPY --from=builder /tmp/psql /usr/local/bin/psql COPY --chown=app:app stressgres/suites/ stressgres/suites/ COPY stressgres/suites/antithesis/ /opt/antithesis/test/v1/paradedb/ USER app ENV RUST_LOG=info ENV PGCLIENTENCODING=UTF8 CMD ["sleep", "infinity"]