CI / Frozen lockfile install (pull_request) Successful in 48s
Switch the app image from node:24-alpine to node:24.19.0-bookworm-slim in both build and runtime stages (Technology-Stack 5.4: glibc Debian base required because argon2 is a native dependency; musl/Alpine causes native-module build surprises), and the db image from postgres:16-alpine to postgres:18-bookworm (Technology-Stack 5.2/5.4/6.2 + golden tuple 7 pin PostgreSQL 18.6; 18-bookworm is the 18.x line on Debian bookworm). Update tests/compose-config.test.mjs so the committed assertions lock in the corrected image bases (db image, Dockerfile build/runtime stages, parser probe).
53 lines
2.5 KiB
Docker
53 lines
2.5 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# @personal-blog/server — EPPP public server application image.
|
|
#
|
|
# [E00-S02-T01] baseline: builds the workspace server package with the pinned
|
|
# toolchain (Node 24.19.0 + pnpm 11.23.0, frozen lockfile) and runs the compiled
|
|
# entrypoint. The server is still a bootstrap placeholder (its module loads and
|
|
# exits cleanly); the Fastify 5 application shell that turns it into a serving
|
|
# process lands in a later story, and the health gate (T02), health endpoint
|
|
# (T03), volume persistence (T04), non-root/read-only hardening and multi-arch
|
|
# targets are later E00-S02 tasks — all out of scope here.
|
|
#
|
|
# Image base: node:24.19.0-bookworm-slim (glibc Debian) per Technology-Stack
|
|
# §5.4 — argon2 is a native dependency and musl/Alpine causes native-module
|
|
# build surprises, so the image must stay on a glibc base.
|
|
|
|
# --- build stage: install the frozen workspace and compile the server --------
|
|
FROM node:24.19.0-bookworm-slim AS build
|
|
WORKDIR /app
|
|
|
|
# Enable the pinned pnpm (11.23.0, via packageManager in the root package.json)
|
|
# with Corepack, which ships with the Node image.
|
|
RUN corepack enable
|
|
|
|
# Copy only the manifests needed for resolution first, so source edits do not
|
|
# invalidate the dependency layer, then install against the committed lockfile
|
|
# (the same `--frozen-lockfile` path CI and developers use). Every workspace
|
|
# package manifest is copied so the in-image workspace matches the lockfile
|
|
# importers exactly (apps/server, packages/core, extensions/example).
|
|
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml tsconfig.base.json ./
|
|
COPY apps/server/package.json apps/server/package.json
|
|
COPY packages/core/package.json packages/core/package.json
|
|
COPY extensions/example/package.json extensions/example/package.json
|
|
RUN pnpm install --frozen-lockfile
|
|
|
|
# Compile the server package (tsc -p apps/server/tsconfig.json -> dist/).
|
|
COPY apps/server apps/server
|
|
RUN pnpm --filter @personal-blog/server build
|
|
|
|
# --- runtime stage: Node 24.19.0 (bookworm-slim) + compiled output only ------
|
|
FROM node:24.19.0-bookworm-slim AS runtime
|
|
WORKDIR /app
|
|
ENV NODE_ENV=production
|
|
|
|
# The workspace install (devDependencies included — image-size pruning is a
|
|
# later E00-S02 concern) plus the compiled server output and manifest.
|
|
COPY --from=build /app/node_modules ./node_modules
|
|
COPY --from=build /app/apps/server/dist ./apps/server/dist
|
|
COPY --from=build /app/apps/server/package.json ./apps/server/package.json
|
|
|
|
EXPOSE 3000
|
|
CMD ["node", "apps/server/dist/index.js"]
|