summaryrefslogtreecommitdiff
path: root/docs/DEPLOY.md
diff options
context:
space:
mode:
authorAnders Betts <anders.betts@gmail.com>2026-09-20 23:09:31 +0200
committerAnders Betts <anders.betts@gmail.com>2026-09-20 23:09:31 +0200
commit19e4d8dcc9c9e76a8c90855cccb4c4553b35389e (patch)
treed014fd0baebc2e269ee6e2f3def2c657aaee3659 /docs/DEPLOY.md
parentfe40173f32b14e012044b39f0f63c2613787e725 (diff)
downloadbokf-19e4d8dcc9c9e76a8c90855cccb4c4553b35389e.tar.gz
bokf-19e4d8dcc9c9e76a8c90855cccb4c4553b35389e.zip
deploy: cross-compile static aarch64 for the Alpine imagev0.1.54
Diffstat (limited to 'docs/DEPLOY.md')
-rw-r--r--docs/DEPLOY.md21
1 files changed, 12 insertions, 9 deletions
diff --git a/docs/DEPLOY.md b/docs/DEPLOY.md
index 7385a8f..6fe6a53 100644
--- a/docs/DEPLOY.md
+++ b/docs/DEPLOY.md
@@ -56,6 +56,8 @@ Normal deploys build an image and recreate the container. While developing,
`scripts/deploy.sh --dev` skips the image entirely:
- the gate (`make` + `make test`) still runs locally,
+- on an architecture mismatch the static aarch64 binaries are
+ cross-compiled here (about 20 s, `deploy/Dockerfile.cross`),
- the binaries are copied into the running container with `docker cp`,
- the daemon is reloaded with `SIGHUP`, which re-execs the binary in place
(in-memory sessions are lost, clients reconnect),
@@ -63,9 +65,7 @@ Normal deploys build an image and recreate the container. While developing,
No image is built and the container is not recreated; a later normal deploy
replaces the copied binaries. Use a descriptive tag, e.g.
-`scripts/deploy.sh --dev v0.2.0-rc1`. Hot reload requires the host to share
-the dev machine's architecture; on a mismatch `--dev` falls back to a full
-remote build.
+`scripts/deploy.sh --dev v0.2.0-rc1`.
## Deploying upgrades
@@ -80,7 +80,8 @@ The script:
1. `make` + `make test` on the dev machine,
2. builds `bokf:<tag>`: locally and ships it with `docker save | gzip | ssh
docker load`, or — when the host runs a different CPU architecture —
- builds it natively on the host from a source tar,
+ cross-compiles the backend here and assembles the image on the host from
+ a source tar,
3. copies `compose.yaml` and writes `BOKF_IMAGE`/`BOKF_TAG` into the host's
`.env` (other keys are preserved),
4. `docker compose up -d --no-build`, then polls the container healthcheck,
@@ -88,11 +89,13 @@ The script:
that is still loaded on the host.
Architecture mismatches are automatic: `uname -m` is compared over SSH and a
-mismatch switches to a remote build of the same Alpine image (compiled inside
-the host's Docker, so the host still needs no toolchain). Override with
-`BOKF_BUILD=local` or `BOKF_BUILD=remote` (also settable in `.env`). The
-runtime image is Alpine and carries `bokfd` + `bokfctl` only; the ncurses TUI
-is a frontend and never shipped.
+mismatch runs `deploy/Dockerfile.cross`, which links `bokfd`/`bokfctl`
+statically for aarch64 (glibc + OpenSSL archives; it runs on the Alpine
+runtime directly, DNS included). The image is then assembled in the host's
+Docker — no compilation there. Override with `BOKF_BUILD=local` or
+`BOKF_BUILD=remote` (also settable in `.env`). The runtime image is Alpine,
+carries `bokfd` + `bokfctl` only (no `libssl3`; the binaries are static) and
+never ships the ncurses TUI, which is a frontend built on the client.
Tags are `git describe` output unless passed. Tag releases (`v*`) so rollback
and support have meaningful versions. The rollback image must still exist on