# syntax=docker/dockerfile:1 # @personal-blog/server — EPPP public server application image. # # [E00-S02-T01/T02/T03] baseline: builds the workspace server package with the # pinned toolchain (Node 24.19.0 + pnpm 11.23.0, frozen lockfile) and runs the # compiled entrypoint. Since T03 the entrypoint is a minimal Node `node:http` # server answering `GET /health` with `{"status":"ok"}` (HTTP 200) on port # 3000, so the app container stays up and the health endpoint succeeds. The # Fastify 5 application shell (and the real HTTP API) lands in a later story; # DB volume persistence (T04) is a Compose-level concern (see compose.yaml — # this image is unchanged), while non-root/read-only hardening (T05/T06) and # multi-arch targets remain later E00-S02 tasks — all out of scope here. # # Image base: node:24.19.0-bookworm-slim (glibc Debian) per Technology-Stack # §5.4 — argon2 is a native dependency and musl/Alpine causes native-module # build surprises, so the image must stay on a glibc base. # --- build stage: install the frozen workspace and compile the server -------- FROM node:24.19.0-bookworm-slim AS build WORKDIR /app # Enable the pinned pnpm (11.23.0, via packageManager in the root package.json) # with Corepack, which ships with the Node image. RUN corepack enable # Copy only the manifests needed for resolution first, so source edits do not # invalidate the dependency layer, then install against the committed lockfile # (the same `--frozen-lockfile` path CI and developers use). Every workspace # package manifest is copied so the in-image workspace matches the lockfile # importers exactly (apps/server, packages/core, extensions/example). COPY package.json pnpm-lock.yaml pnpm-workspace.yaml tsconfig.base.json ./ COPY apps/server/package.json apps/server/package.json COPY packages/core/package.json packages/core/package.json COPY extensions/example/package.json extensions/example/package.json RUN pnpm install --frozen-lockfile # Compile the server package (tsc -p apps/server/tsconfig.json -> dist/). COPY apps/server apps/server RUN pnpm --filter @personal-blog/server build # --- runtime stage: Node 24.19.0 (bookworm-slim) + compiled output only ------ FROM node:24.19.0-bookworm-slim AS runtime WORKDIR /app ENV NODE_ENV=production # The workspace install (devDependencies included — image-size pruning is a # later E00-S02 concern) plus the compiled server output and manifest. COPY --from=build /app/node_modules ./node_modules COPY --from=build /app/apps/server/dist ./apps/server/dist COPY --from=build /app/apps/server/package.json ./apps/server/package.json EXPOSE 3000 CMD ["node", "apps/server/dist/index.js"]