The subtree is in place, so everything that used to fetch and patch core at
build time now just copies it.
tools/build.sh copies wordpress/ — no download, no checksum step,
because there is nothing to fetch and nothing to
trust that is not already in the repository
docker/Dockerfile COPY wordpress/ instead of curl + sha256 + patch;
the build args and the `patch` package are gone
docker-compose.yml no WP_VERSION / WP_URL / WP_SHA256 to keep in step
tools/update-wordpress.sh is rewritten around what the subtree makes
possible. It imports the pristine release onto sirius-press/wordpress-upstream
and then `git subtree merge`s that branch, which three-way merges upstream
against the fork's own commit. A patch either applies with fuzz and hopes or
fails and leaves you re-deriving the change by hand; a merge conflict is
resolved once, in the file, and the next release merges against the
resolution.
patches/ survives as documentation rather than mechanism, and is now
generated: tools/refresh-patches.sh diffs the subtree against the pristine
import and rewrites the directory, with --check for CI. It answers the
question anyone auditing a fork asks first — what exactly did you change
inside WordPress? — in a minute, which `git log wordpress/` cannot, because
that log is mostly upstream imports. Generated documentation stays true; a
hand-maintained record of a core diff drifts, and a stale one is worse than
none because people trust it.
One test change worth noting: the syntax sweep no longer walks all of
wordpress/. It lints the fork's own PHP plus every core file patches/ says
the fork touches, which keeps the suite at seven seconds instead of a minute
while still covering the only core file that can break.
90 lines
3 KiB
YAML
90 lines
3 KiB
YAML
# Sirius Press — a complete self-hosted stack.
|
|
#
|
|
# Three containers: MariaDB, PHP-FPM with the patched WordPress baked in, and
|
|
# nginx in front. Only nginx is published.
|
|
#
|
|
# The volume layout is the part worth reading. WordPress core comes from the
|
|
# repository's `wordpress/` subtree, is baked into the image, and is refilled
|
|
# into the document root on every start — so `docker compose build && up -d`
|
|
# genuinely upgrades it — the usual arrangement, where the whole document root is a
|
|
# volume, freezes core at whatever version first created the volume and turns
|
|
# every security release into a manual migration. What people actually need to
|
|
# keep — uploads, plugins and themes they installed, and wp-config.php — is
|
|
# what gets a volume.
|
|
#
|
|
# cp .env.example .env # then edit it
|
|
# docker compose up -d
|
|
|
|
name: sirius-press
|
|
|
|
services:
|
|
db:
|
|
image: mariadb:11.4
|
|
restart: unless-stopped
|
|
environment:
|
|
MARIADB_DATABASE: ${DB_NAME:-wordpress}
|
|
MARIADB_USER: ${DB_USER:-wordpress}
|
|
MARIADB_PASSWORD: ${DB_PASSWORD:?set DB_PASSWORD in .env}
|
|
MARIADB_ROOT_PASSWORD: ${DB_ROOT_PASSWORD:?set DB_ROOT_PASSWORD in .env}
|
|
MARIADB_AUTO_UPGRADE: "1"
|
|
command:
|
|
# utf8mb4 throughout: a post containing an emoji should not be a
|
|
# database error, and WordPress has assumed this for years.
|
|
- --character-set-server=utf8mb4
|
|
- --collation-server=utf8mb4_unicode_ci
|
|
volumes:
|
|
- db:/var/lib/mysql
|
|
healthcheck:
|
|
test: ["CMD", "healthcheck.sh", "--connect", "--innodb_initialized"]
|
|
interval: 10s
|
|
timeout: 5s
|
|
retries: 12
|
|
|
|
app:
|
|
build:
|
|
context: ..
|
|
dockerfile: docker/Dockerfile
|
|
restart: unless-stopped
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
environment:
|
|
WORDPRESS_DB_HOST: db
|
|
WORDPRESS_DB_NAME: ${DB_NAME:-wordpress}
|
|
WORDPRESS_DB_USER: ${DB_USER:-wordpress}
|
|
WORDPRESS_DB_PASSWORD: ${DB_PASSWORD:?set DB_PASSWORD in .env}
|
|
WORDPRESS_SITE_URL: ${SITE_URL:-}
|
|
WORDPRESS_DEBUG: ${WP_DEBUG:-false}
|
|
SIRIUS_PRESS_KEY: ${SIRIUS_PRESS_KEY:-}
|
|
volumes:
|
|
- config:/var/www/config
|
|
# The document root is a volume so nginx can read the same files. It is
|
|
# refilled from the image on every start, so this does not pin core.
|
|
- core:/var/www/html
|
|
- uploads:/var/www/html/wp-content/uploads
|
|
- plugins:/var/www/html/wp-content/plugins
|
|
- themes:/var/www/html/wp-content/themes
|
|
|
|
web:
|
|
image: nginx:1.27-alpine
|
|
restart: unless-stopped
|
|
depends_on:
|
|
- app
|
|
ports:
|
|
- "${HTTP_PORT:-80}:80"
|
|
volumes:
|
|
- ./nginx/default.conf:/etc/nginx/conf.d/default.conf:ro
|
|
# nginx serves static files directly and only proxies PHP, so it needs
|
|
# to see the same tree. Read-only: the web tier has no business writing.
|
|
- core:/var/www/html:ro
|
|
- uploads:/var/www/html/wp-content/uploads:ro
|
|
- plugins:/var/www/html/wp-content/plugins:ro
|
|
- themes:/var/www/html/wp-content/themes:ro
|
|
|
|
volumes:
|
|
db:
|
|
config:
|
|
core:
|
|
uploads:
|
|
plugins:
|
|
themes:
|