From 5bbcfa9b6d5ddb9e70d65ac17b7095e17979f83a Mon Sep 17 00:00:00 2001 From: bot-implementer Date: Sat, 29 Aug 2026 01:13:30 +0000 Subject: [PATCH] feat: make amd64 and arm64 image build targets (E00-S02-T07) --- apps/server/Dockerfile | 14 ++++++++------ compose.yaml | 20 +++++++++++++++++--- 2 files changed, 25 insertions(+), 9 deletions(-) diff --git a/apps/server/Dockerfile b/apps/server/Dockerfile index 8b99809..18a879a 100644 --- a/apps/server/Dockerfile +++ b/apps/server/Dockerfile @@ -8,12 +8,14 @@ # server answering `GET /health` with `{"status":"ok"}` (HTTP 200) on port # 3000, so the app container stays up and the health endpoint succeeds. The # Fastify 5 application shell (and the real HTTP API) lands in a later story; -# DB volume persistence (T04) and read-only root filesystem (T06) are -# Compose-level concerns (see compose.yaml — the `db-data` volume mount and the -# app service's `read_only: true` + `/tmp` tmpfs; this image is unchanged), -# while multi-arch build targets (T07) remains a later E00-S02 task — out of -# scope here. Since T05 the runtime stage drops root privileges (runs as the -# image's non-root `node` user). +# DB volume persistence (T04), read-only root filesystem (T06) and multi-arch +# build targets (T07) are Compose-level concerns (see compose.yaml — the +# `db-data` volume mount, the app service's `read_only: true` + `/tmp` tmpfs, +# and its `build.platforms` list; this image is unchanged: both stages use the +# official multi-arch node:24.19.0-bookworm-slim base and the build has no +# native dependencies, so the amd64/arm64 targets need no image change). Since +# T05 the runtime stage drops root privileges (runs as the image's non-root +# `node` user). # # Image base: node:24.19.0-bookworm-slim (glibc Debian) per Technology-Stack # §5.4 — argon2 is a native dependency and musl/Alpine causes native-module diff --git a/compose.yaml b/compose.yaml index a703515..08903b4 100644 --- a/compose.yaml +++ b/compose.yaml @@ -1,4 +1,4 @@ -# EPPP Docker Compose baseline — [E00-S02-T01..T06] +# EPPP Docker Compose baseline — [E00-S02-T01..T07] # # `docker compose up -d` starts both the database (PostgreSQL) and the # application (@personal-blog/server). Rollback: `docker compose down`. @@ -30,8 +30,15 @@ # the only writable path. Rollback: drop `read_only`/`tmpfs` from the `app` # service. # -# Explicitly out of scope for T01..T06 (land in later E00-S02 tasks): -# - multi-arch build targets (T07), secrets not embedded (T08) +# Multi-arch build targets (T07): the `app` service's `build.platforms` list +# declares `linux/amd64` and `linux/arm64` (Compose Build spec `platforms`), so +# `docker compose build` produces a multi-platform image for both +# architectures. `docker compose up` still builds and runs the host platform, +# so local runs and the T01..T06 real-stack probes are unaffected. Rollback: +# drop the `platforms` list from the `app` build config. +# +# Explicitly out of scope for T01..T07 (land in a later E00-S02 task): +# - secrets not embedded (T08) # # All values have defaults so `docker compose up -d` works from a clean clone # without a .env file (a committed .env.example template lands in E00-S04). @@ -66,6 +73,13 @@ services: build: context: . dockerfile: apps/server/Dockerfile + # T07: multi-arch build targets — `docker compose build` produces a + # multi-platform image for linux/amd64 and linux/arm64 (Compose Build + # spec `platforms`). `docker compose up` builds/runs the host platform, + # so the T01..T06 real-stack probes are unaffected. + platforms: + - linux/amd64 + - linux/arm64 environment: DATABASE_URL: postgres://eppp:eppp@db:5432/eppp ports: