Initial release: self-hosted client photo gallery
ci / docker (push) Successful in 13s

Rust (axum + sqlx) API and worker sharing a Postgres-backed job queue
(SKIP LOCKED, heartbeat, reaper, typed statuses), S3 storage with derived
keys and a fully private bucket, OIDC photographer login with per-request
allowlist checks, client share links with argon2 passwords and lockout,
cookie-based image authorization with sliding expiry, hand-rolled
spec-compliant streaming ZIP downloads with exact Content-Length,
React + Vite gallery frontend, single Docker image, Helm chart for
external S3 + Postgres, and Gitea CI.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-07-17 13:12:42 +02:00
co-authored by Claude
commit 16d2a56a78
55 changed files with 11962 additions and 0 deletions
+30
View File
@@ -0,0 +1,30 @@
# ---- frontend ----
FROM node:22-alpine AS frontend
WORKDIR /app
COPY frontend/package.json frontend/package-lock.json* ./
RUN npm install
COPY frontend/ ./
RUN npm run build
# ---- backend ----
FROM rust:1-bookworm AS backend
WORKDIR /app
COPY Cargo.toml Cargo.lock* ./
COPY src ./src
COPY migrations ./migrations
RUN cargo build --release --bins
# ---- runtime (shared by api and worker) ----
FROM debian:bookworm-slim
RUN apt-get update \
&& apt-get install -y --no-install-recommends exiftool ca-certificates \
&& rm -rf /var/lib/apt/lists/*
RUN useradd --system --uid 1000 photos
WORKDIR /app
COPY --from=backend /app/target/release/server /app/target/release/worker /usr/local/bin/
COPY --from=frontend /app/dist /app/static
ENV STATIC_DIR=/app/static
USER photos
EXPOSE 8080
# The worker deployment overrides this with: command ["worker"]
CMD ["server"]