# Overlay: let the container publish the homepage's /source mirror. # # docker compose -f docker-compose.yml -f docker-compose.source.yml up -d # # `archilyzer source publish` (run by the homepage build) mirrors this repo's # `main` — but the image has no .git (.dockerignore keeps it out, and it would be # stale the day after the build anyway). This mounts the HOST's git common dir, # read-only, at /data/source.git and points ARCHILYZER_SOURCE_REPO at it; # common/publish/source.ts reads that before it looks for a checkout. Nothing in # the container writes to it: the publish clones it into scratch first. # # ARCHILYZER_SOURCE_HOST_DIR is the host path, default `./.git` — right for a # plain clone. In a git WORKTREE `.git` is a file; use the primary checkout's # `.git` (`git rev-parse --git-common-dir` prints it). # # The entrypoint marks /data/source.git as a git safe.directory (the files # belong to your host user, the container runs as root). The scrub rules and # the denylist the publish needs live in the config volume # (ARCHILYZER_CONFIG_DIR, /data/config/archilyzer): `docker compose cp` them in. # RUNNING_IN_DOCKER.md, "Publish the archive". # # The long mount syntax with create_host_path: false, on purpose: the short form # makes a missing host path (a tarball install, a typo) into an empty root-owned # directory on the host. This way `up` fails and names the path instead. services: editor: environment: ARCHILYZER_SOURCE_REPO: /data/source.git volumes: - type: bind source: ${ARCHILYZER_SOURCE_HOST_DIR:-./.git} target: /data/source.git read_only: true bind: create_host_path: false