Sign inSign up

codeboxindia/rust-tauri-tooling

By codeboxindia

•Updated about 1 month ago

Pinned Ubuntu 22.04 toolchain for building & testing Rust workspaces and Tauri apps

Image
Languages & frameworks
Developer tools
0

279

codeboxindia/rust-tauri-tooling repository overview

⁠rust-tauri-tooling

A pinned, reproducible Linux toolchain image for building and testing Rust workspaces and Tauri⁠ apps — bundled with the supply-chain and secret-scanning gates a real CI pipeline runs. It is built on ubuntu:22.04 so that it byte-matches the GitHub Actions ubuntu-22.04 runner (glibc 2.35, WebKitGTK 4.1): a build on your laptop and a build in hosted CI resolve the same toolchain and behave the same way.

docker pull codeboxindia/rust-tauri-tooling:1.95.0-20260708

Platforms: linux/amd64 and linux/arm64 under one multi-arch tag — Apple Silicon and x86 machines both pull their native variant automatically.


⁠The reasoning: why we built this

Tauri sits at an awkward intersection. It is a Rust project, so it wants the Rust toolchain, clippy, nextest, and the RustSec supply-chain tools. It is also a webview desktop app, so on Linux it needs the full WebKitGTK native stack and a headless display to render under. And a serious project wants secret scanning and dependency-policy gates on top. Stitching those three worlds together correctly — at pinned, matching versions — is fiddly, and getting it slightly wrong is the usual reason "works on my machine" diverges from "works in CI."

We kept re-solving that setup: on each contributor's machine, in CI, and again whenever a version drifted. So we froze the whole environment into one image, built around four decisions:

  1. Match the CI runner exactly. The base is ubuntu:22.04 — the same OS, glibc, and WebKitGTK as the GitHub ubuntu-22.04 runner. A green local run and a green hosted run mean the same thing. That parity is the entire point; it is why we did not start from a lighter or differently-based image.
  2. Never bake project source into the image. There is no COPY of application code. You bind-mount your repo at /work at run time. The image is a pure toolchain — nothing about it is coupled to any one project, so it is genuinely reusable.
  3. Pin everything. Rust, Node, every cargo tool, gitleaks — all exact versions. A build today and a build months from now resolve an identical environment. No floating "latest" that silently moves under you.
  4. One artifact for every machine. A single multi-arch tag serves Apple Silicon dev laptops, x86 CI, and x86 Windows/WSL2 dev — no per-machine image, no "which tag do I pull" confusion.

The result is that spinning up a correct, complete Rust+Tauri build environment is a docker pull instead of a page of setup steps that each machine gets subtly wrong.

⁠What you'd use it for

  • Local pre-commit / CI-parity gate. Run your full test/lint/audit gate locally and trust that a pass means CI passes, because the environment is identical.
  • Hosted CI. Use it directly as the container in a GitHub Actions / GitLab CI job so the hosted run and the local run share one definition.
  • Contributor onboarding. A new contributor gets the entire toolchain — right Rust, right Node, WebKitGTK, the audit tools — in one pull, with nothing to install on the host.
  • Reproducible / archival builds. Because everything is pinned and multi-arch, a build is reproducible across time and across x86/ARM.
  • Headless GUI checks. WebKitGTK + xvfb are present, so webview boot/smoke tests and WebDriver E2E runs work with no display attached.

⁠How it's different from other images

This imageOfficial rust:*Community Tauri imagesRoll-your-own
CI-runner parity (Ubuntu 22.04, glibc 2.35, WebKitGTK 4.1)✅ deliberate❌ Debian-based⚠️ varies by distro⚠️ up to you
WebKitGTK + Tauri Linux deps✅❌✅⚠️ manual
Node + npm✅ pinned❌✅ often unpinned⚠️ manual
Supply-chain gates (cargo-deny, cargo-audit, gitleaks)✅❌❌⚠️ manual
Test/fuzz tooling (nextest, cargo-fuzz)✅❌❌⚠️ manual
Fully version-pinned✅✅ (Rust only)⚠️ usually not⚠️ up to you
Multi-arch (amd64 + arm64), one tag✅✅⚠️ varies⚠️ up to you
No project source baked in✅✅✅—

Short version: rust:* is Rust-only and Debian-based (breaks the runner parity we depend on). Community Tauri images give you Rust + Node + WebKitGTK but typically drop the audit/secret/fuzz gates and float their versions. This image is the union — the Tauri GUI stack and the CI gates and exact pinning and runner parity — in one place.

⁠What's inside

CategoryContentsWhy it's here
Rustrustup with Rust 1.95.0 (stable, default) + nightly (with rust-src), rustfmt, clippyCompile, format, lint; nightly for fuzzing
Test / fuzzcargo-nextest, cargo-fuzzFast parallel test runner; libFuzzer-based fuzzing
Supply-chaincargo-deny, cargo-audit, gitleaks 8.30.1License/ban/advisory policy + committed-secret scanning
NodeNode 24.14.1 + npm (verified against nodejs.org SHASUMS)Tauri frontends and JS build/test steps
Tauri Linux depslibwebkit2gtk-4.1-dev, libayatana-appindicator3-dev, librsvg, xvfb/xauthThe webview render stack + headless display
Build essentialsbuild-essential, pkg-config, libssl-dev, clang, llvm, lldC/-sys crate builds; lld for fast linking
Convenienceripgrep, git, curl, ca-certificatesEveryday in-container searches and fetches

⁠How to use it

Interactive shell against the current directory (default CMD is bash, WORKDIR is /work):

docker run --rm -it -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708

One-shot commands:

# full test suite with nextest
docker run --rm -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708 \
  cargo nextest run --workspace

# lint + format + dependency policy in one go
docker run --rm -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708 \
  bash -lc 'cargo clippy --all-targets -- -D warnings && cargo fmt --all --check && cargo deny check'

# headless webview / E2E under a virtual display
docker run --rm -v "$PWD":/work codeboxindia/rust-tauri-tooling:1.95.0-20260708 \
  xvfb-run -a npm run e2e
⁠docker compose
services:
  tooling:
    image: codeboxindia/rust-tauri-tooling:1.95.0-20260708
    working_dir: /work
    # Match your host uid so bind-mounted writes are not root-owned (Linux hosts):
    user: "${HOST_UID:-1000}:${HOST_GID:-1000}"
    volumes:
      - .:/work
      # Persist caches across runs so rebuilds stay fast:
      - cargo-registry:/usr/local/cargo/registry
      - target:/work-target
    environment:
      CARGO_TARGET_DIR: /work-target
volumes:
  cargo-registry:
  target:
⁠In GitHub Actions
jobs:
  gate:
    runs-on: ubuntu-latest
    container: codeboxindia/rust-tauri-tooling:1.95.0-20260708
    steps:
      - uses: actions/checkout@v4
      - run: cargo nextest run --workspace
      - run: cargo deny check && gitleaks detect --no-banner --redact
⁠A note on the user

The image runs as root by default and also contains a non-root builder user at uid 501 (the default first-user id on macOS). Pass --user <uid>:<gid> — or compose user: — to match your host so bind-mounted files stay owned by you. The cargo/npm cache directories are initially owned by uid 501; if you run as a very different uid, either reuse 501 or mount your own cache volumes.

⁠What this image does not do

It is a Linux toolchain. It builds and tests the platform-independent Rust core of a project and the Linux Tauri bundle. It cannot produce a Windows (.msi/WebView2) or macOS (.app) Tauri bundle — those require their respective native toolchains. Running it under Docker Desktop on Windows (WSL2) or macOS works fine for the Rust-core and Linux legs; it just can't cross-build the other platforms' native shells.

⁠Tags

Tags are <rust-version>-<YYYYMMDD>, e.g. 1.95.0-20260708. The date advances whenever a pinned tool version changes; the Rust version leads so you can read the toolchain at a glance.

⁠License

The image bundles third-party toolchains and tools, each under its own upstream license (Rust: MIT/Apache-2.0; Node: MIT; gitleaks: MIT; the cargo tools: MIT/Apache-2.0 or similar). No application source is included.

Tag summary

Content type

Image

Digest

sha256:874a9ad17…

Size

1.6 GB

Last updated

about 1 month ago

docker pull codeboxindia/rust-tauri-tooling:1.95.0-20260827