# Dockerfile for Foxhunt Monolithic HFT Trading System # OPTIONAL - For development/testing only # Production should run on bare metal for sub-50μs latency ################################################################# # Build Stage - Multi-architecture support ################################################################# FROM --platform=$BUILDPLATFORM rust:1.75-slim-bookworm AS builder # Build arguments for cross-compilation ARG TARGETPLATFORM ARG BUILDPLATFORM ARG TARGETOS ARG TARGETARCH # Install build dependencies RUN apt-get update && apt-get install -y \ pkg-config \ libssl-dev \ libpq-dev \ ca-certificates \ curl \ build-essential \ cmake \ git \ clang \ llvm \ && rm -rf /var/lib/apt/lists/* # Install CUDA toolkit for GPU support (conditional) RUN if [ "$TARGETARCH" = "amd64" ]; then \ wget https://developer.download.nvidia.com/compute/cuda/repos/debian11/x86_64/cuda-keyring_1.0-1_all.deb && \ dpkg -i cuda-keyring_1.0-1_all.deb && \ apt-get update && \ apt-get install -y cuda-toolkit-12-0 && \ rm -rf /var/lib/apt/lists/* && \ rm cuda-keyring_1.0-1_all.deb; \ fi # Setup Rust target for cross-compilation RUN case "$TARGETARCH" in \ "amd64") RUST_TARGET=x86_64-unknown-linux-gnu ;; \ "arm64") RUST_TARGET=aarch64-unknown-linux-gnu ;; \ *) echo "Unsupported architecture: $TARGETARCH" && exit 1 ;; \ esac && \ rustup target add $RUST_TARGET # Create build user RUN useradd -m -u 1000 builder # Set working directory WORKDIR /app # Copy workspace configuration COPY Cargo.toml Cargo.lock ./ # Copy all module Cargo.toml files for dependency resolution COPY core/Cargo.toml ./core/ COPY ml/Cargo.toml ./ml/ COPY risk/Cargo.toml ./risk/ COPY data/Cargo.toml ./data/ COPY tli/Cargo.toml ./tli/ # Create dummy source files for dependency pre-compilation RUN mkdir -p core/src ml/src risk/src data/src tli/src && \ echo "pub fn main() {}" > core/src/lib.rs && \ echo "pub fn main() {}" > ml/src/lib.rs && \ echo "pub fn main() {}" > risk/src/lib.rs && \ echo "pub fn main() {}" > data/src/lib.rs && \ echo "fn main() {}" > tli/src/main.rs # Pre-compile dependencies (cached layer) RUN cargo build --release --workspace RUN rm -rf core/src ml/src risk/src data/src tli/src target/release/.fingerprint/core-* target/release/.fingerprint/ml-* target/release/.fingerprint/risk-* target/release/.fingerprint/data-* target/release/.fingerprint/tli-* # Copy actual source code COPY . . # Set target architecture for compilation RUN case "$TARGETARCH" in \ "amd64") RUST_TARGET=x86_64-unknown-linux-gnu ;; \ "arm64") RUST_TARGET=aarch64-unknown-linux-gnu ;; \ esac && \ echo "Building for target: $RUST_TARGET" # Build the monolithic trading system with performance optimizations ENV RUSTFLAGS="-C target-cpu=native -C opt-level=3 -C lto=fat -C codegen-units=1" RUN cargo build --release --bin tli # Strip debug symbols for smaller binary RUN strip target/release/tli ################################################################# # Runtime Stage - Minimal, secure production image ################################################################# FROM debian:bookworm-slim # Install runtime dependencies RUN apt-get update && apt-get install -y \ ca-certificates \ libssl3 \ libpq5 \ curl \ htop \ procps \ net-tools \ && rm -rf /var/lib/apt/lists/* # Install NVIDIA runtime for GPU support (conditional) RUN if command -v nvidia-smi > /dev/null 2>&1; then \ distribution=$(. /etc/os-release;echo $ID$VERSION_ID) && \ curl -s -L https://nvidia.github.io/nvidia-docker/gpgkey | apt-key add - && \ curl -s -L https://nvidia.github.io/nvidia-docker/$distribution/nvidia-docker.list | tee /etc/apt/sources.list.d/nvidia-docker.list && \ apt-get update && \ apt-get install -y nvidia-container-toolkit && \ rm -rf /var/lib/apt/lists/*; \ fi # Create non-root user with specific UID/GID for security RUN groupadd -g 1000 foxhunt && \ useradd -r -u 1000 -g foxhunt -d /app -s /bin/bash -c "Foxhunt Trading System" foxhunt # Set working directory WORKDIR /app # Copy binary from builder stage COPY --from=builder /app/target/release/tli /app/foxhunt # Copy configuration and data directories COPY --chown=foxhunt:foxhunt config/ /app/config/ COPY --chown=foxhunt:foxhunt data/ /app/data/ # Create necessary directories with proper permissions RUN mkdir -p /app/logs /app/tmp /app/models /app/cache /app/certificates && \ chown -R foxhunt:foxhunt /app && \ chmod 755 /app/foxhunt && \ chmod -R 750 /app/config /app/certificates && \ chmod -R 755 /app/logs /app/tmp /app/models /app/cache # Create volume mount points VOLUME ["/app/logs", "/app/models", "/app/cache", "/app/certificates"] # Security hardening RUN echo "foxhunt:x:1000:1000::/app:/bin/bash" >> /etc/passwd && \ echo "foxhunt:x:1000:" >> /etc/group # Switch to non-root user USER foxhunt # Health check endpoint HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \ CMD curl -f http://localhost:${FOXHUNT_HTTP_PORT:-8080}/health || exit 1 # Network ports EXPOSE ${FOXHUNT_HTTP_PORT:-8080} EXPOSE ${FOXHUNT_GRPC_PORT:-50051} EXPOSE ${FOXHUNT_METRICS_PORT:-9090} EXPOSE ${FOXHUNT_WEBSOCKET_PORT:-8081} # Environment variables with secure defaults ENV FOXHUNT_ENV=production \ FOXHUNT_SERVICE_HOST=0.0.0.0 \ FOXHUNT_HTTP_PORT=8080 \ FOXHUNT_GRPC_PORT=50051 \ FOXHUNT_METRICS_PORT=9090 \ FOXHUNT_WEBSOCKET_PORT=8081 \ FOXHUNT_LOG_LEVEL=info \ FOXHUNT_LOG_FORMAT=json \ FOXHUNT_CONFIG_PATH=/app/config \ FOXHUNT_DATA_PATH=/app/data \ FOXHUNT_MODELS_PATH=/app/models \ FOXHUNT_CACHE_PATH=/app/cache \ FOXHUNT_CERTIFICATES_PATH=/app/certificates \ RUST_LOG=info \ RUST_BACKTRACE=0 \ RUST_LOG_STYLE=never # Performance tuning environment variables ENV FOXHUNT_THREAD_POOL_SIZE=0 \ FOXHUNT_MAX_CONNECTIONS=1000 \ FOXHUNT_CONNECTION_TIMEOUT=30 \ FOXHUNT_REQUEST_TIMEOUT=60 \ FOXHUNT_LATENCY_TARGET_MS=50 \ FOXHUNT_BATCH_SIZE=1000 # Security environment variables ENV FOXHUNT_SECURITY_ENABLED=true \ FOXHUNT_TLS_ENABLED=true \ FOXHUNT_RATE_LIMITING_ENABLED=true \ FOXHUNT_METRICS_ENABLED=true \ FOXHUNT_TRACING_ENABLED=true # GPU configuration (if available) ENV CUDA_VISIBLE_DEVICES="" \ FOXHUNT_GPU_ENABLED=auto \ FOXHUNT_GPU_MEMORY_FRACTION=0.8 # Entry point script for flexible configuration COPY --chown=foxhunt:foxhunt docker/entrypoint.sh /app/entrypoint.sh RUN chmod +x /app/entrypoint.sh # Labels for container metadata LABEL maintainer="Foxhunt Development Team" \ version="1.0.0" \ description="Foxhunt HFT Trading System - Production Monolithic Deployment" \ vendor="Foxhunt" \ org.opencontainers.image.title="Foxhunt HFT Trading System" \ org.opencontainers.image.description="High-frequency trading system with ML intelligence" \ org.opencontainers.image.version="1.0.0" \ org.opencontainers.image.vendor="Foxhunt" \ org.opencontainers.image.licenses="MIT OR Apache-2.0" \ org.opencontainers.image.source="https://github.com/user/foxhunt" \ org.opencontainers.image.documentation="https://github.com/user/foxhunt/docs" # Run the application ENTRYPOINT ["/app/entrypoint.sh"] CMD ["/app/foxhunt"]