# Multi-stage build for the ASP.NET Core API. FROM mcr.microsoft.com/dotnet/sdk:10.0 AS build WORKDIR /src # Copy solution + project files first for layer-cached restore. COPY Directory.Build.props ./ COPY src/InboxIntel.Domain/InboxIntel.Domain.csproj src/InboxIntel.Domain/ COPY src/InboxIntel.Application/InboxIntel.Application.csproj src/InboxIntel.Application/ COPY src/InboxIntel.Infrastructure/InboxIntel.Infrastructure.csproj src/InboxIntel.Infrastructure/ COPY src/InboxIntel.Api/InboxIntel.Api.csproj src/InboxIntel.Api/ RUN dotnet restore src/InboxIntel.Api/InboxIntel.Api.csproj COPY src/ src/ RUN dotnet publish src/InboxIntel.Api/InboxIntel.Api.csproj -c Release -o /app/publish /p:UseAppHost=false FROM mcr.microsoft.com/dotnet/aspnet:10.0 AS runtime WORKDIR /app # The slim aspnet:10.0 image dropped libgssapi_krb5, which Npgsql tries to load during # connection negotiation ("Cannot load library libgssapi_krb5.so.2"). Harmless for password # auth but noisy and a latent failure on some paths — install the Kerberos runtime lib. RUN apt-get update \ && apt-get install -y --no-install-recommends libgssapi-krb5-2 \ && rm -rf /var/lib/apt/lists/* COPY --from=build /app/publish . # V-12: run as the non-root 'app' user shipped in the .NET 8 images. Pre-create the # DataProtection key directory owned by that user so the (initially empty) 'keys' # volume inherits app ownership on first mount and key persistence still works. # NOTE: an EXISTING root-owned keys volume must be recreated for this to take effect. RUN mkdir -p /keys && chown -R app:app /keys /app USER app EXPOSE 8080 ENTRYPOINT ["dotnet", "InboxIntel.Api.dll"]