Chuyển đến nội dung chính

第 20 課:Rust 的 Docker 和 CI/CD

多階段 Docker 建置(建置器 + 臨時/無發行版)。 Cargo-Chef 用於快取相依性。 GitHub Actions CI/CD,交叉編譯。貨物拒絕、貨物審計。 Clippy,rustfmt。

💻 程式設計 — 第 20 課 第 20 課:Rust 的 Docker 和 CI/CD

Rust:從基礎到高級

第 6 部分:測試、CI/CD 和生產

亞洲開發網

1. 多階段Docker構建

# Stage 1: Chef — cache dependencies
FROM rust:1.79-slim AS chef
RUN cargo install cargo-chef
WORKDIR /app

FROM chef AS planner
COPY . .
RUN cargo chef prepare --recipe-path recipe.json

# Stage 2: Build
FROM chef AS builder
COPY --from=planner /app/recipe.json recipe.json
RUN cargo chef cook --release --recipe-path recipe.json  # Cache deps
COPY . .
RUN cargo build --release

# Stage 3: Runtime — minimal image
FROM gcr.io/distroless/cc-debian12 AS runtime
COPY --from=builder /app/target/release/my-app /app
EXPOSE 3000
CMD ["/app"]
# docker-compose.yml
services:
  app:
    build: .
    ports:
      - "3000:3000"
    environment:
      - DATABASE_URL=postgres://user:pass@db:5432/mydb
      - RUST_LOG=info
    depends_on:
      - db
      - redis
  db:
    image: postgres:16-alpine
    environment:
      POSTGRES_DB: mydb
      POSTGRES_USER: user
      POSTGRES_PASSWORD: pass
  redis:
    image: redis:7-alpine

2. GitHub Actions CI/CD

name: Rust CI

on:
  push:
    branches: [main]
  pull_request:

env:
  CARGO_TERM_COLOR: always

jobs:
  check:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: dtolnay/rust-toolchain@stable
        with:
          components: clippy, rustfmt
      - uses: Swatinem/rust-cache@v2

      - name: Format check
        run: cargo fmt --check

      - name: Clippy
        run: cargo clippy -- -D warnings

      - name: Tests
        run: cargo test

      - name: Security audit
        run: |
          cargo install cargo-audit
          cargo audit

  build:
    needs: check
    runs-on: ubuntu-latest
    if: github.ref == 'refs/heads/main'
    steps:
      - uses: actions/checkout@v4
      - uses: docker/build-push-action@v5
        with:
          push: true
          tags: ghcr.io/${{ github.repository }}:latest

3. 程式碼品質工具

# Clippy — linter
cargo clippy -- -D warnings -W clippy::pedantic

# Audit — security vulnerabilities
cargo audit

# Deny — license & dependency checks
cargo deny check

# Outdated dependencies
cargo outdated
# deny.toml
[advisories]
vulnerability = "deny"
unmaintained = "warn"

[licenses]
allow = ["MIT", "Apache-2.0", "BSD-2-Clause", "BSD-3-Clause"]

4.交叉編譯

# Cài target
rustup target add x86_64-unknown-linux-musl
rustup target add aarch64-unknown-linux-gnu

# Build static binary (musl)
cargo build --release --target x86_64-unknown-linux-musl

# Cross — cross-compile dễ dàng
cargo install cross
cross build --release --target aarch64-unknown-linux-gnu

下一篇: 可觀察性和監控。