Files
mrcharles 10e2b7c7ed feat: add FX Cloudron package (DevOps-Tools) [#640]
FX 0.9.48 ("poor man's function as a service") as the 13th package:
pre-compiled goreleaser release binary with sha256 pin on
cloudron/base:4.0.0. fx is a CLI with no user concept, so the package
is a workstation: pinned binary + persistent workspace
(functions/ssh/kube) driven from the Cloudron web terminal, with an
auth-proxied landing page as the only HTTP surface (httpAuth proxy).
Deploys target remote Docker hosts over key-based SSH or Kubernetes
via FX_KUBECONF. Build green; runtime smoke (landing page, workspace
seeding, fx -v) green. Docs gardened to 13 packages.

Ticket: https://projects.knownelement.com/issues/640
2026-09-01 19:39:53 -05:00

61 lines
2.8 KiB
Docker

# FX Cloudron Package
#
# fx (metrue/fx) is "poor man's function as a service": a CLI that turns a
# stateless function file (JavaScript, Python, Go, Ruby, Java, PHP, Perl,
# Crystal, Rust, Julia, D) into a running HTTP service on your own Docker
# host or Kubernetes cluster, in seconds. fx is a DRIVER-side tool: it
# packages the function, ships it to the target over SSH (key-based) or
# the K8s API, and the TARGET runs the container.
#
# Cloudron app containers have no Docker daemon, so this package is the
# operator's fx WORKSTATION: the pinned fx binary plus a persistent
# workspace (/app/data/functions, /app/data/ssh, /app/data/kube), driven
# from the Cloudron web terminal. Deploy targets are remote Docker hosts
# (--host user@host --ssh_key ...) or a Kubernetes cluster (FX_KUBECONF
# or -C kubeconf).
#
# Authentication: fx has NO user concept — no web UI, no accounts, no
# SSO hooks — so the auth-gate verdict is the proxy row (AGENTS.md
# matrix). The manifest declares httpAuth.type = proxy: Cloudron's auth
# proxy gates the landing page, the only HTTP surface this app has.
# Access to the terminal/workspace itself is Cloudron's app access list.
#
# Upstream: https://github.com/metrue/fx
# - Release 0.9.48-alpha.d91a7a0 (2021-06-10) is the latest published
# release and what the official scripts/install.sh installs; the
# binary reports version 0.9.48. Repo master (2023) has no newer
# release.
# - Ships goreleaser tarballs; the linux/amd64 asset is
# fx_<tag>_Tux_64-bit.tar.gz, glibc-built -> needs an Ubuntu base.
FROM cloudron/base:4.0.0
ARG FX_TAG=0.9.48-alpha.d91a7a0
ARG FX_SHA256=1ed8a40f81038ca9e33aa09dba2184448b2efa3ed6373936e9f849f50200910f
# Pre-compiled-binaries pattern (JOURNAL pattern #5): pinned release
# download behind a sha256 gate (checksum taken from the upstream
# checksums.txt asset). Building the 2021-era codebase (go 1.12 modules
# + packr assets) from source would buy nothing over the official
# release binary.
RUN curl -fsSL -o /tmp/fx.tar.gz \
"https://github.com/metrue/fx/releases/download/${FX_TAG}/fx_${FX_TAG}_Tux_64-bit.tar.gz" \
&& echo "${FX_SHA256} /tmp/fx.tar.gz" | sha256sum -c - \
&& tar -xzf /tmp/fx.tar.gz -C /usr/local/bin --exclude='*.md' --exclude='LICENSE*' \
&& chmod +x /usr/local/bin/fx \
&& rm -f /tmp/fx.tar.gz \
&& /usr/local/bin/fx -v
# Static landing page served on the Cloudron HTTP port (platform health
# check + auth-proxied usage guide). fx itself has no daemon, so the
# page server is the only long-running process. start.sh seeds the
# /app/data workspace on first run; it is made executable on the host,
# not at build time (Cloudron gotcha).
COPY status.html /app/code/status/index.html
COPY start.sh /app/start.sh
WORKDIR /app/data
EXPOSE 8000
CMD ["/bin/bash", "/app/start.sh"]