forked from Maintainerr/Maintainerr
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
137 lines (102 loc) · 4.43 KB
/
Copy pathDockerfile
File metadata and controls
137 lines (102 loc) · 4.43 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
FROM node:26.3.0-alpine3.22@sha256:c7932b9e5e337b0e733d6e16abc1b0e104759e8b05e59ed56586cce967d26dfe AS base
LABEL Description="Contains the Maintainerr Docker image"
FROM base AS builder
WORKDIR /app
# Native dependencies for node-canvas (cairo) and sharp (vips)
RUN apk add --no-cache \
build-base \
python3 \
pkgconfig \
cairo-dev \
pango-dev \
jpeg-dev \
giflib-dev \
pixman-dev \
librsvg-dev
RUN npm install -g corepack@latest && corepack enable
# Copy only files needed to resolve/install dependencies first (better Docker layer caching)
COPY package.json yarn.lock .yarnrc.yml turbo.json ./
RUN corepack install
COPY .yarn/releases ./.yarn/releases
COPY apps/server/package.json ./apps/server/package.json
COPY apps/ui/package.json ./apps/ui/package.json
COPY packages/contracts/package.json ./packages/contracts/package.json
RUN yarn install --network-timeout 99999999
# Copy the rest of the repository after deps are installed
COPY . .
RUN <<EOF cat >> ./apps/ui/.env
VITE_BASE_PATH=/__PATH_PREFIX__
EOF
RUN yarn turbo build
# Only install production dependencies to reduce image size
RUN yarn workspaces focus --all --production
# When all packages are hoisted, there is no node_modules folder. Ensure these folders always have a node_modules folder to COPY later on.
RUN mkdir -p ./packages/contracts/node_modules
RUN mkdir -p ./apps/server/node_modules
FROM base AS runner
WORKDIR /opt/app
# Application code is only ever read at runtime, so 755 is enough for any uid
# the container is started with (see the `user` directive) to load it, while
# keeping it unwritable.
# copy root node_modules
COPY --from=builder --chmod=755 --chown=node:node /app/node_modules ./node_modules
# Copy standalone server
COPY --from=builder --chmod=755 --chown=node:node /app/apps/server/dist ./apps/server/dist
COPY --from=builder --chmod=755 --chown=node:node /app/apps/server/package.json ./apps/server/package.json
COPY --from=builder --chmod=755 --chown=node:node /app/apps/server/node_modules ./apps/server/node_modules
# copy UI output to API to be served statically. Read-only like the rest:
# start.sh stages a copy under the data directory and resolves the BASE_PATH
# placeholder there, so nothing rewrites this tree.
COPY --from=builder --chmod=755 --chown=node:node /app/apps/ui/dist ./apps/server/dist/ui
# Copy bundled fonts for overlay rendering
COPY --from=builder --chmod=755 --chown=node:node /app/apps/server/assets ./apps/server/dist/assets
# Copy packages/contracts
COPY --from=builder --chmod=755 --chown=node:node /app/packages/contracts/dist ./packages/contracts/dist
COPY --from=builder --chmod=755 --chown=node:node /app/packages/contracts/package.json ./packages/contracts/package.json
COPY --from=builder --chmod=755 --chown=node:node /app/packages/contracts/node_modules ./packages/contracts/node_modules
# 755 keeps these executable by whichever uid the docker user directive selects.
COPY --chmod=755 --chown=node:node docker/start.sh /opt/app/start.sh
COPY --chmod=755 --chown=node:node docker/healthcheck.sh /opt/app/healthcheck.sh
# Create required directories. World-writable on purpose: the image cannot know
# which uid the container will run as, and this is the one tree that uid has to
# write. It only applies to a fresh named volume - a bind mount keeps the host's
# own ownership and modes.
RUN mkdir -m 777 /opt/data && \
mkdir -m 777 /opt/data/logs && \
chown -R node:node /opt/data
# Runtime dependencies for node-canvas (cairo) and sharp (vips)
RUN apk --update --no-cache add \
curl \
cairo \
pango \
jpeg \
giflib \
pixman \
librsvg
ARG NODE_ENV=production
ENV NODE_ENV=${NODE_ENV}
ARG DEBUG=false
ENV DEBUG=${DEBUG}
ARG UI_PORT=6246
ENV UI_PORT=${UI_PORT}
ARG UI_HOSTNAME=0.0.0.0
ENV UI_HOSTNAME=${UI_HOSTNAME}
# Hash of the last GIT commit
ARG GIT_SHA
ENV GIT_SHA=$GIT_SHA
ENV DATA_DIR=/opt/data
# container version type. develop, stable, edge,.. a release=stable
ARG VERSION_TAG=develop
ENV VERSION_TAG=$VERSION_TAG
ARG BASE_PATH
ENV BASE_PATH=${BASE_PATH}
# Temporary workaround for https://github.com/libuv/libuv/pull/4141
ENV UV_USE_IO_URING=0
USER node
EXPOSE 6246
# Readiness probe: 200 while the DB answers, 503 otherwise. start-period covers
# the first boot (UI base-path rewrite + Nest bootstrap + migrations).
HEALTHCHECK --interval=30s --timeout=5s --start-period=40s --retries=3 \
CMD ["/opt/app/healthcheck.sh"]
VOLUME [ "/opt/data" ]
ENTRYPOINT ["/opt/app/start.sh"]