# Multi-stage build for Foxhunt Backtesting Service # Wave 71 Agent 8: Production-optimized Docker image # ============================================================================= # Builder Stage # ============================================================================= FROM rust:1.89-slim-bookworm AS builder # Install build dependencies RUN apt-get update && apt-get install -y \ pkg-config \ libssl-dev \ protobuf-compiler \ && rm -rf /var/lib/apt/lists/* # Set working directory WORKDIR /build # Copy workspace manifests COPY Cargo.toml Cargo.lock ./ # Copy entire workspace (simple direct build) COPY . . # Build the application RUN cargo build --release -p backtesting_service # ============================================================================= # Runtime Stage # ============================================================================= FROM debian:bookworm-slim # Install runtime dependencies RUN apt-get update && apt-get install -y \ ca-certificates \ libssl3 \ curl \ && rm -rf /var/lib/apt/lists/* # Download and install grpc_health_probe RUN curl -sSL https://github.com/grpc-ecosystem/grpc-health-probe/releases/download/v0.4.25/grpc_health_probe-linux-amd64 \ -o /usr/local/bin/grpc_health_probe && \ chmod +x /usr/local/bin/grpc_health_probe # Create non-root user RUN groupadd --system --gid 1000 foxhunt && \ useradd --system --uid 1000 --gid foxhunt --shell /bin/bash foxhunt # Create application directories RUN mkdir -p /app/config /app/logs /app/data /app/results && \ chown -R foxhunt:foxhunt /app # Set working directory WORKDIR /app # Copy binary from builder COPY --from=builder /build/target/release/backtesting_service ./backtesting_service RUN chmod +x ./backtesting_service # Switch to non-root user USER foxhunt # Expose gRPC and metrics ports EXPOSE 50052 9093 # Health check using grpc_health_probe HEALTHCHECK --interval=10s --timeout=5s --start-period=30s --retries=3 \ CMD /usr/local/bin/grpc_health_probe -addr=localhost:50052 || exit 1 # Run the application ENTRYPOINT ["./backtesting_service"]