diff --git a/CLAUDE.md b/CLAUDE.md index 13b5b6cc..c951e393 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -35,6 +35,20 @@ CI runs on **Gitea Actions** (`.gitea/workflows/`), not GitHub. Use the `gh` CLI only against the mirror if one exists; the canonical remote is `gitea.tourolle.paris`. +> **🔴 CI installs no system tools.** Never add an `apt-get`, `rustup`, +> `sdkmanager`, mingw/nsis, or any other *toolchain/system-package* install to a +> CI workflow step. Every build, test, and packaging **tool** must already live +> in the Docker image the job runs in — the unified builder (`Dockerfile.builder` +> → `gitea.tourolle.paris/dtourolle/jellytau-builder`) for Android/Linux/Windows, +> or `Dockerfile.arch` for Arch. If a job needs a tool the image lacks, **add it +> to the image, rebuild + push it** (`scripts/build-builder-image.sh`), and use +> it from CI — do not install it at job time. This keeps builds reproducible and +> fast, and is why the packaging stages are thin `FROM ${BUILDER_IMAGE}` layers. +> +> `bun install` (fetching the project's own JS deps per the lockfile) is **not** +> a violation — that's project dependencies, not a toolchain. The rule is about +> system tools, not npm/bun/cargo *packages* declared by the project. + ## Before Committing - Frontend: `bun run check` and `bun run test` must pass. diff --git a/Dockerfile b/Dockerfile index c39b1c36..208a561b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,11 @@ # Multi-stage build for JellyTau - Tauri Jellyfin client +# +# The desktop packaging stages (desktop-linux-build, windows-cross) build FROM +# the unified registry builder image, which carries every packaging tool. Declared +# here (before the first FROM) so it's in scope for those stages' FROM lines. +# Override for local iteration: --build-arg BUILDER_IMAGE=jellytau-builder:latest +ARG BUILDER_IMAGE=gitea.tourolle.paris/dtourolle/jellytau-builder:latest + FROM ubuntu:24.04 AS builder ENV DEBIAN_FRONTEND=noninteractive \ @@ -108,6 +115,30 @@ RUN cd src-tauri && cargo fetch && cd .. && \ bun run tauri android build --apk true && \ echo "APK build complete!" +# Desktop packaging stages build FROM the unified registry builder image (see the +# BUILDER_IMAGE ARG at the top), which already carries every packaging tool +# (rpm/file for Linux, mingw-w64 + nsis + the x86_64-pc-windows-gnu rust target +# for Windows). ONE source of dependency truth, shared with CI — no per-stage +# apt/rustup here. + +# Linux desktop packaging environment (deb + rpm; Arch is Dockerfile.arch). +# Thin layer over the builder — the actual build runs at container-run time on +# the bind-mounted source (see docker-compose.yml / scripts/build-desktop-linux.sh), +# matching the `dev` service model. Run standalone with: +# docker run --rm -v "$PWD:/app" -v "$PWD/dist:/app/dist" \ +# bash -c "OUTPUT_DIR=/app/dist scripts/build-desktop-linux.sh" +FROM ${BUILDER_IMAGE} AS desktop-linux-build +WORKDIR /app +CMD ["bash", "-c", "OUTPUT_DIR=/app/dist scripts/build-desktop-linux.sh"] + +# Windows cross-compile environment (MSVC target via cargo-xwin). Video works via +# WebView2 and audio via the webview