This repository builds Docker images for STRATfinder
This closely follows the original structure of the STRATfinder code.
docker run --rm -ti \
--user $(id -u):$(id -g) \
--volume $PWD:/data stratfinder:latest \
/data/<path to json config file> \
/data/< path to overlap file otherwise use: ""> \
/data/< path to today file > \
/data/< path to output file > \
/data/< path to beta output file > \
/data/< path to yesterday file otherwise use: ""> \
< path to the stratfinder directory otherwise use: ""> \--user $(id -u):$(id -g)use the system's user in the container to get file permissions right-v $PWD:/data stratfinder:latest \mounts the current working directory to/datainside the container/data/settings_STRATfinder_cl61_urbi_Paris.jsonis the path to the stratfinder config file
an example for a single file could be:
- the
/dataprefix is due to the mount of the current working directory - we read a file from the
dailydirectory - we write the output files to a
outputdirectory
# !/bin/bash
set -eux pipefail
docker run --rm -ti \
--user $(id -u):$(id -g) \
--volume $PWD:/data stratfinder:latest \
/data/stratfinder_settings_cl61.json \
"" \
/data/daily/20260316.nc \
/data/output/20260316_stratfinder.nc \
/data/output/20260315_beta.nc \
"" \
""A small python script (stratfinder.py) wraps the docker command, however hides all
user permission, mounting, and path complexities. Note that all paths must be relative
to the current working directory since this is mounted. Moving up (../) does not work.
with this setup
- Docker installed and running
- GNU Make
- Git
- The
stratfinder/submodule checked out
If the submodule is not initialized yet:
git submodule update --initBuild with defaults:
make buildDefault values:
STRATFINDER_REF=masterMATLAB_VERSION=r2025bIMAGE_NAME=stratfinder
The build creates two tags:
<IMAGE_NAME>:<STRATFINDER_VERSION>-<MATLAB_VERSION><IMAGE_NAME>:latest
Example (typical):
stratfinder:<master-version>-r2025bstratfinder:latest
Before the Docker build starts, make build automatically applies patch files from
patches/ in strict order:
0.patch,1.patch,2.patch, ...,n.patch
Build fails if numbering is not consecutive from 0.
If a patch is already applied, it is detected and skipped.
After the build finishes (or fails), the stratfinder/ submodule is automatically
restored to the master branch.
Build a specific STRATfinder tag:
make build STRATFINDER_REF=v2025.10Build a specific STRATfinder commit:
make build STRATFINDER_REF=e0c6239Build with another MATLAB Runtime version:
Note that you will first have to compile the binary and place it in bin. Currently only one binary is present - with the patch applied.
make build MATLAB_VERSION=r2024bBuild with a custom image name:
make build IMAGE_NAME=my-stratfinderYou can combine overrides:
make build STRATFINDER_REF=v2025.10 MATLAB_VERSION=r2024b IMAGE_NAME=my-stratfinderUse a custom patch directory:
make build PATCH_DIR=patchesmake helpList images:
docker images | grep stratfinderIf you used a custom image name:
docker images | grep my-stratfinderRemove built image tags managed by this Makefile:
make cleanNotes:
make cleanalways tries to remove<IMAGE_NAME>:latestwhen it exists.- Tagged image removal (
<IMAGE_NAME>:<tag>) depends onIMAGE_TAGbeing set in the environment or make invocation. - If an image does not exist, cleanup prints a skip message and continues.
Images are published to ghcr.io via the Build and Push Docker Image workflow,
which is triggered manually.
Via the GitHub UI: Actions → Build and Push Docker Image → Run workflow. Fill in
stratfinder_ref (default: master) and matlab_version (default: r2025b).
The published image will be tagged as:
ghcr.io/<owner>/<repo>:<stratfinder-version>-<matlab-version>(e.g.v2025.10-r2025b)ghcr.io/<owner>/<repo>:latest
A signed build-provenance attestation is generated and pushed alongside each image.