DocumentationDeployment

Rust · 0.1.0

Docker

Build and run the packaged Rust server with persistent storage.

What the image contains

The Dockerfile builds the web interface, then embeds it in the Rust server binary. The runtime contains certificate roots, timezone data and the entrypoint. There is no separate application web server to configure. Start from the local build example and check container logs if startup fails.

docker logs --tail 100 memos
docker inspect memos --format '{{.State.Status}}'
curl --fail http://127.0.0.1:5230/healthz

Keep the data outside the container

Mount persistent storage at /var/opt/memos. The entrypoint prepares ownership and drops privileges for the server process. Custom bind mounts must be writable by the configured runtime user; avoid world-writable permissions. If you change MEMOS_DATA, update the mount accordingly. MEMOS_DSN_FILE is supported by the container entrypoint for file-based database secrets.

Update deliberately

Use a recorded source commit and a distinct image tag for each build. Back up database and attachment storage, stop the old writer, then start the new image with the same configuration and volume. A successful health response is only a startup check; also verify sign-in, a memo and an attachment. See upgrade and rollback.

Check runtime identity and mounted secrets

The packaged entrypoint defaults to MEMOS_UID=10001 and MEMOS_GID=10001, prepares data-directory ownership when it starts as root, and then drops privileges. If you override the runtime user, arrange write access to the data volume and read access to secret files beforehand. A MEMOS_DSN_FILE error can mean the file is unreadable to that runtime account; setting both MEMOS_DSN and MEMOS_DSN_FILE is explicitly rejected. Do not print either value while debugging.