# Sirius Press — PHP-FPM image with the patched WordPress baked in. # # Core comes from this repository's `wordpress/` subtree, not from a download # and not from the official `wordpress` image. That image ships whatever # version it was tagged with, and the fork's core patch is pinned to an exact # one; applying a fork's patch to a different core is how a setup wizard ends # up half rewritten. Copying the vendored tree makes the image contain exactly # what `git log wordpress/` describes, with nothing fetched at build time. # # Core is staged at /opt/sirius-press/core, not at the document root. The # entrypoint copies it into place on every start, which is what makes # `docker compose build --pull && up -d` a real upgrade: the usual layout, # where the document root is itself a volume, pins core to whatever version # first created that volume and turns every security release into a manual # migration. # # GMP is installed because the wallet cryptography runs in PHP. Without it the # fork falls back to BCMath, which works and is roughly twenty times slower — # unavoidable on a shared host, wasteful in a container we control. FROM php:8.3-fpm-bookworm RUN set -eux; \ apt-get update; \ apt-get install -y --no-install-recommends \ ca-certificates curl \ libfreetype6-dev libjpeg62-turbo-dev libpng-dev libwebp-dev \ libzip-dev libgmp-dev libicu-dev \ ; \ docker-php-ext-configure gd --with-freetype --with-jpeg --with-webp; \ docker-php-ext-install -j"$(nproc)" \ bcmath gd gmp intl mysqli opcache zip exif \ ; \ rm -rf /var/lib/apt/lists/* # Settings a WordPress host wants and the PHP image does not set. RUN { \ echo 'upload_max_filesize = 64M'; \ echo 'post_max_size = 64M'; \ echo 'memory_limit = 256M'; \ echo 'max_execution_time = 120'; \ echo 'opcache.memory_consumption = 128'; \ echo 'opcache.max_accelerated_files = 10000'; \ echo 'opcache.revalidate_freq = 2'; \ echo 'expose_php = Off'; \ } > /usr/local/etc/php/conf.d/sirius-press.ini # --- core, from the subtree -------------------------------------------------- COPY wordpress/ /opt/sirius-press/core/ RUN set -eux; \ test -f /opt/sirius-press/core/wp-includes/version.php; \ sed -n "s/.*wp_version = '\\(.*\\)'.*/\\1/p" \ /opt/sirius-press/core/wp-includes/version.php \ > /opt/sirius-press/core/.sirius-core-version; \ echo "vendored WordPress $(cat /opt/sirius-press/core/.sirius-core-version)" # --- the fork ----------------------------------------------------------------- # # The patch is already applied in the subtree, so there is nothing to patch # here. patches/ is carried for auditing, not for building. WORKDIR /opt/sirius-press/core COPY plugins/ /opt/sirius-press/core/wp-content/plugins/ COPY mu-plugins/ /opt/sirius-press/core/wp-content/mu-plugins/ COPY docker/entrypoint.sh /usr/local/bin/sirius-entrypoint RUN chmod +x /usr/local/bin/sirius-entrypoint; \ mkdir -p /var/www/html /var/www/config; \ chown -R www-data:www-data /var/www/html /var/www/config WORKDIR /var/www/html ENTRYPOINT ["sirius-entrypoint"] CMD ["php-fpm"]