# Sirius Press — PHP-FPM image with a verified, patched WordPress baked in. # # The image builds core rather than inheriting the official `wordpress` image # on purpose. That image ships whatever WordPress version it was tagged with, # and the patch series here is pinned to an exact one; silently applying a # fork's patches to a different core is how a setup wizard ends up half # rewritten. Downloading the pinned tarball and checking its hash during the # build makes the version an explicit, verifiable property of the image. # # Core is installed to /opt/sirius-press/core, not to the document root. The # entrypoint copies it into place on every start, which is what makes # `docker compose build --pull && up -d` a real upgrade: the usual layout, # where the document root is itself a volume, pins core to whatever version # first created that volume and turns every security release into a manual # migration. # # GMP is installed because the wallet cryptography runs in PHP. Without it the # fork falls back to BCMath, which works and is roughly twenty times slower — # unavoidable on a shared host, wasteful in a container we control. FROM php:8.3-fpm-bookworm ARG WP_VERSION ARG WP_URL ARG WP_SHA256 RUN set -eux; \ apt-get update; \ apt-get install -y --no-install-recommends \ ca-certificates curl patch \ libfreetype6-dev libjpeg62-turbo-dev libpng-dev libwebp-dev \ libzip-dev libgmp-dev libicu-dev \ ; \ docker-php-ext-configure gd --with-freetype --with-jpeg --with-webp; \ docker-php-ext-install -j"$(nproc)" \ bcmath gd gmp intl mysqli opcache zip exif \ ; \ rm -rf /var/lib/apt/lists/* # Settings a WordPress host wants and the PHP image does not set. RUN { \ echo 'upload_max_filesize = 64M'; \ echo 'post_max_size = 64M'; \ echo 'memory_limit = 256M'; \ echo 'max_execution_time = 120'; \ echo 'opcache.memory_consumption = 128'; \ echo 'opcache.max_accelerated_files = 10000'; \ echo 'opcache.revalidate_freq = 2'; \ echo 'expose_php = Off'; \ } > /usr/local/etc/php/conf.d/sirius-press.ini # --- core, verified ----------------------------------------------------------- RUN set -eux; \ curl -fsSL -o /tmp/wp.tar.gz "$WP_URL"; \ echo "$WP_SHA256 /tmp/wp.tar.gz" | sha256sum -c -; \ mkdir -p /opt/sirius-press; \ tar -xzf /tmp/wp.tar.gz -C /tmp; \ mv /tmp/wordpress /opt/sirius-press/core; \ rm -rf /tmp/wp.tar.gz # --- the fork ----------------------------------------------------------------- WORKDIR /opt/sirius-press/core COPY patches/ /tmp/patches/ RUN set -eux; \ for p in /tmp/patches/*.patch; do \ patch -p1 -F3 --forward --silent < "$p" \ || { echo "patch $p did not apply to WordPress $WP_VERSION"; exit 1; }; \ done; \ rm -rf /tmp/patches; \ echo "$WP_VERSION" > /opt/sirius-press/core/.sirius-core-version COPY plugins/ /opt/sirius-press/core/wp-content/plugins/ COPY mu-plugins/ /opt/sirius-press/core/wp-content/mu-plugins/ COPY docker/entrypoint.sh /usr/local/bin/sirius-entrypoint RUN chmod +x /usr/local/bin/sirius-entrypoint; \ mkdir -p /var/www/html /var/www/config; \ chown -R www-data:www-data /var/www/html /var/www/config WORKDIR /var/www/html ENTRYPOINT ["sirius-entrypoint"] CMD ["php-fpm"]