-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
71 lines (50 loc) · 2.42 KB
/
Copy pathDockerfile
File metadata and controls
71 lines (50 loc) · 2.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
# ==============================================================================
# PEC - Proxy Extension Corp
# Production Multi-Stage Dockerfile
# ==============================================================================
FROM node:20-alpine AS builder
WORKDIR /app
# Install build dependencies for native modules if required
RUN apk add --no-cache python3 make g++ git
# Copy dependency manifests (package-lock.json is committed - npm ci works)
COPY package.json package-lock.json* ./
# Install all dependencies (including devDependencies for build)
RUN if [ -f package-lock.json ]; then npm ci; else npm install; fi
# Copy application source code
COPY . .
# Build application bundle / static assets
RUN npm run build
# ==============================================================================
# Production Runner (runtime dependencies only, no sources, no devDependencies)
# ==============================================================================
FROM node:20-alpine AS runner
WORKDIR /app
# Install tzdata and dumb-init for proper signal handling
RUN apk add --no-cache tzdata dumb-init curl bash
ENV NODE_ENV=production
ENV PORT=3000
ENV HOST=0.0.0.0
ENV DATA_DIR=/app/data
# Create application directories with non-root ownership
RUN addgroup -g 1001 -S pecgroup && \
adduser -u 1001 -S pecuser -G pecgroup
# Runtime dependencies only: the bundle (dist/server.cjs) externalizes packages
COPY --from=builder --chown=pecuser:pecgroup /app/package.json /app/package-lock.json* ./
RUN if [ -f package-lock.json ]; then npm ci --omit=dev; else npm install --omit=dev; fi && npm cache clean --force
# Built bundle only - server.ts/src are not needed at runtime
COPY --from=builder --chown=pecuser:pecgroup /app/dist ./dist
# Dashboard static assets served by express.static (see server.ts)
COPY --from=builder --chown=pecuser:pecgroup /app/public ./public
# Writable directories for credentials, runtime state and extension artifacts.
# Mount /app/data as a volume: every persistent store lives there (see
# docker-compose.yml environment) and survives rebuilds and redeploys.
RUN mkdir -p /app/data /app/extension /app/dist/updates && \
chown -R pecuser:pecgroup /app
VOLUME ["/app/data"]
USER pecuser
EXPOSE 3000
# Health check probe
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
CMD curl -f http://localhost:3000/healthz || exit 1
ENTRYPOINT ["/usr/bin/dumb-init", "--"]
CMD ["node", "dist/server.cjs"]