# lab's runtime: the tool runtime, carrying this module's code, and the toolchain the lab's suite # builds the mesh with (novox/hq ADR 0172). It reaches the machine's virtualisation and container # runtime through their sockets, so what it raises is what a hand run on this machine raises. # # Every download is pinned by its checksum: an image that builds the mesh is the last place to take # whatever an upstream serves today. ARG BUILD_BASE ARG RUNTIME_BASE FROM ${BUILD_BASE} AS build WORKDIR /app/modules/lab COPY . . RUN node /app/node_modules/typescript/bin/tsc tools/index.ts tools/runs.ts \ --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist FROM ${RUNTIME_BASE} RUN apt-get update \ && apt-get install -y --no-install-recommends git make ca-certificates curl \ && rm -rf /var/lib/apt/lists/* RUN curl -fsSL -o /tmp/go.tgz https://go.dev/dl/go1.26.8.linux-amd64.tar.gz \ && echo "d0f743b33e8d8945e6b1f432edd15785c70507121d6e2a723b21285eddf8b57b /tmp/go.tgz" | sha256sum -c - \ && tar -C /usr/local -xzf /tmp/go.tgz && rm /tmp/go.tgz RUN curl -fsSL -o /usr/local/bin/incus https://github.com/lxc/incus/releases/download/v7.5.1/bin.linux.incus.x86_64 \ && echo "7bd6223b369f4d693fcde695bd8549a73b5b3d403735329212483702aa22c179 /usr/local/bin/incus" | sha256sum -c - \ && chmod 0755 /usr/local/bin/incus RUN curl -fsSL -o /tmp/docker.tgz https://download.docker.com/linux/static/stable/x86_64/docker-28.5.2.tgz \ && echo "ea90cfd12e1eeb12aa1c971741adb8bd4ed88e2a574eaac13f5029a1dbc6300d /tmp/docker.tgz" | sha256sum -c - \ && tar -C /tmp -xzf /tmp/docker.tgz docker/docker && mv /tmp/docker/docker /usr/local/bin/docker && rm -rf /tmp/docker /tmp/docker.tgz ENV PATH=/usr/local/go/bin:$PATH COPY --from=build /app/modules/lab/dist /app/modules/lab/dist ENV MESH_TOOL_MODULES=/app/modules/lab/dist/tools/index.js