Pinned Ubuntu 22.04 toolchain for building & testing Rust workspaces and Tauri apps
279
A pinned, reproducible Linux toolchain image for building and testing Rust workspaces and
Tauri apps — bundled with the supply-chain and secret-scanning gates a real
CI pipeline runs. It is built on ubuntu:22.04 so that it byte-matches the GitHub Actions
ubuntu-22.04 runner (glibc 2.35, WebKitGTK 4.1): a build on your laptop and a build in hosted CI
resolve the same toolchain and behave the same way.
docker pull codeboxindia/rust-tauri-tooling:1.95.0-20260708
Platforms: linux/amd64 and linux/arm64 under one multi-arch tag — Apple Silicon and x86
machines both pull their native variant automatically.
Tauri sits at an awkward intersection. It is a Rust project, so it wants the Rust toolchain, clippy,
nextest, and the RustSec supply-chain tools. It is also a webview desktop app, so on Linux it needs
the full WebKitGTK native stack and a headless display to render under. And a serious project
wants secret scanning and dependency-policy gates on top. Stitching those three worlds
together correctly — at pinned, matching versions — is fiddly, and getting it slightly wrong is
the usual reason "works on my machine" diverges from "works in CI."
We kept re-solving that setup: on each contributor's machine, in CI, and again whenever a version drifted. So we froze the whole environment into one image, built around four decisions:
ubuntu:22.04 — the same OS, glibc, and WebKitGTK
as the GitHub ubuntu-22.04 runner. A green local run and a green hosted run mean the same thing.
That parity is the entire point; it is why we did not start from a lighter or differently-based
image.COPY of application code. You
bind-mount your repo at /work at run time. The image is a pure toolchain — nothing about it is
coupled to any one project, so it is genuinely reusable.The result is that spinning up a correct, complete Rust+Tauri build environment is a docker pull
instead of a page of setup steps that each machine gets subtly wrong.
xvfb are present, so webview boot/smoke tests and
WebDriver E2E runs work with no display attached.| This image | Official rust:* | Community Tauri images | Roll-your-own | |
|---|---|---|---|---|
| CI-runner parity (Ubuntu 22.04, glibc 2.35, WebKitGTK 4.1) | ✅ deliberate | ❌ Debian-based | ⚠️ varies by distro | ⚠️ up to you |
| WebKitGTK + Tauri Linux deps | ✅ | ❌ | ✅ | ⚠️ manual |
| Node + npm | ✅ pinned | ❌ | ✅ often unpinned | ⚠️ manual |
Supply-chain gates (cargo-deny, cargo-audit, gitleaks) | ✅ | ❌ | ❌ | ⚠️ manual |
Test/fuzz tooling (nextest, cargo-fuzz) | ✅ | ❌ | ❌ | ⚠️ manual |
| Fully version-pinned | ✅ | ✅ (Rust only) | ⚠️ usually not | ⚠️ up to you |
| Multi-arch (amd64 + arm64), one tag | ✅ | ✅ | ⚠️ varies | ⚠️ up to you |
| No project source baked in | ✅ | ✅ | ✅ | — |
Short version: rust:* is Rust-only and Debian-based (breaks the runner parity we depend on).
Community Tauri images give you Rust + Node + WebKitGTK but typically drop the audit/secret/fuzz
gates and float their versions. This image is the union — the Tauri GUI stack and the CI gates
and exact pinning and runner parity — in one place.
| Category | Contents | Why it's here |
|---|---|---|
| Rust | rustup with Rust 1.95.0 (stable, default) + nightly (with rust-src), rustfmt, clippy | Compile, format, lint; nightly for fuzzing |
| Test / fuzz | cargo-nextest, cargo-fuzz | Fast parallel test runner; libFuzzer-based fuzzing |
| Supply-chain | cargo-deny, cargo-audit, gitleaks 8.30.1 | License/ban/advisory policy + committed-secret scanning |
| Node | Node 24.14.1 + npm (verified against nodejs.org SHASUMS) | Tauri frontends and JS build/test steps |
| Tauri Linux deps | libwebkit2gtk-4.1-dev, libayatana-appindicator3-dev, librsvg, xvfb/xauth | The webview render stack + headless display |
| Build essentials | build-essential, pkg-config, libssl-dev, clang, llvm, lld | C/-sys crate builds; lld for fast linking |
| Convenience | ripgrep, git, curl, ca-certificates | Everyday in-container searches and fetches |
Interactive shell against the current directory (default CMD is bash, WORKDIR is /work):
docker run --rm -it -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708
One-shot commands:
# full test suite with nextest
docker run --rm -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708 \
cargo nextest run --workspace
# lint + format + dependency policy in one go
docker run --rm -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708 \
bash -lc 'cargo clippy --all-targets -- -D warnings && cargo fmt --all --check && cargo deny check'
# headless webview / E2E under a virtual display
docker run --rm -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708 \
xvfb-run -a npm run e2e
services:
tooling:
image: codeboxindia/rust-tauri-tooling:1.95.0-20260708
working_dir: /work
# Match your host uid so bind-mounted writes are not root-owned (Linux hosts):
user: "${HOST_UID:-1000}:${HOST_GID:-1000}"
volumes:
- .:/work
# Persist caches across runs so rebuilds stay fast:
- cargo-registry:/usr/local/cargo/registry
- target:/work-target
environment:
CARGO_TARGET_DIR: /work-target
volumes:
cargo-registry:
target:
jobs:
gate:
runs-on: ubuntu-latest
container: codeboxindia/rust-tauri-tooling:1.95.0-20260708
steps:
- uses: actions/checkout@v4
- run: cargo nextest run --workspace
- run: cargo deny check && gitleaks detect --no-banner --redact
The image runs as root by default and also contains a non-root builder user at uid 501
(the default first-user id on macOS). Pass --user <uid>:<gid> — or compose user: — to match your
host so bind-mounted files stay owned by you. The cargo/npm cache directories are initially owned by
uid 501; if you run as a very different uid, either reuse 501 or mount your own cache volumes.
It is a Linux toolchain. It builds and tests the platform-independent Rust core of a project and
the Linux Tauri bundle. It cannot produce a Windows (.msi/WebView2) or macOS (.app)
Tauri bundle — those require their respective native toolchains. Running it under Docker Desktop on
Windows (WSL2) or macOS works fine for the Rust-core and Linux legs; it just can't cross-build the
other platforms' native shells.
Tags are <rust-version>-<YYYYMMDD>, e.g. 1.95.0-20260708. The date advances whenever a pinned
tool version changes; the Rust version leads so you can read the toolchain at a glance.
The image bundles third-party toolchains and tools, each under its own upstream license (Rust: MIT/Apache-2.0; Node: MIT; gitleaks: MIT; the cargo tools: MIT/Apache-2.0 or similar). No application source is included.
Content type
Image
Digest
sha256:874a9ad17…
Size
1.6 GB
Last updated
about 1 month ago
docker pull codeboxindia/rust-tauri-tooling:1.95.0-20260827