Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
80 lines (62 loc) · 2.92 KB
/
Copy pathDockerfile
File metadata and controls
80 lines (62 loc) · 2.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
FROM node:24-alpine AS node-base
# dependencies for the build
FROM node-base AS deps
WORKDIR /app
COPY package.json yarn.lock ./
RUN yarn install --frozen-lockfile --non-interactive --ignore-scripts && yarn cache clean
# runtime-only dependencies, kept apart so the final image never sees devDependencies
FROM node-base AS prod-deps
WORKDIR /app
COPY package.json yarn.lock ./
RUN yarn install --frozen-lockfile --non-interactive --ignore-scripts --production && yarn cache clean
# build env
FROM deps AS build
COPY . .
# Runtime build metadata (surfaced in the footer + /api metrics). The reusable
# Harbor workflow passes these as build-args; regenerate build-info.json from
# them so the bundled values reflect the actual build. Local builds without
# these args keep the tracked REPLACE_WITH_* placeholders untouched.
ARG BUILD_VERSION
ARG BUILD_BRANCH
ARG BUILD_COMMIT
# .next/cache is a multi-hundred-MB webpack FS cache; it must not leak into COPY --from=build below
RUN if [ -n "$BUILD_COMMIT" ]; then \
printf '{"version":"%s","branch":"%s","commit":"%s"}\n' \
"$BUILD_VERSION" "$BUILD_BRANCH" "$BUILD_COMMIT" > build-info.json; \
fi \
&& NODE_NO_BUILD_DYNAMICS=true yarn build \
&& rm -rf .next/cache
# runtime image
FROM node-base AS runner
ARG BASE_PATH=""
ARG DEFAULT_CHAIN="1"
ENV NODE_ENV=production \
NEXT_TELEMETRY_DISABLED=1 \
BASE_PATH=$BASE_PATH \
DEFAULT_CHAIN=$DEFAULT_CHAIN
WORKDIR /app
COPY --from=prod-deps /app/node_modules ./node_modules
COPY --from=build /app/.next ./.next
# next.config.mjs is re-evaluated on server start and writes only
# public/runtime/window-env.js. It is the sole runtime-writable path: under
# readOnlyRootFilesystem mount an emptyDir at /app/public/runtime (uid 1000)
COPY --from=build /app/public ./public
RUN rm -rf public/runtime && mkdir public/runtime && chown node public/runtime
COPY --from=build /app/package.json /app/next.config.mjs /app/next-logger.config.cjs /app/env-dynamics.mjs /app/build-info.json /app/server.mjs ./
COPY --from=build /app/scripts ./scripts
# next-logger.config.cjs preloads ./utilsApi/*.cjs at runtime
COPY --from=build /app/utilsApi ./utilsApi
# ARG does not cross stages; re-declared here so the labels resolve
ARG BUILD_VERSION
ARG BUILD_COMMIT
LABEL org.opencontainers.image.source="https://github.com/lidofinance/csm-widget" \
org.opencontainers.image.version="$BUILD_VERSION" \
org.opencontainers.image.revision="$BUILD_COMMIT"
USER node
EXPOSE 3000
# start-period covers app.prepare(); k8s ignores this and uses its own probes
HEALTHCHECK --interval=10s --timeout=3s --start-period=30s --retries=3 \
CMD wget -q -O /dev/null "http://localhost:${PORT:-3000}/api/health" || exit 1
# node must be PID 1 to receive SIGTERM and exit truthfully; yarn and `node --run`
# both forward the signal but exit non-zero. Mirrors the `start` script — keep in sync.
CMD ["node", "-r", "next-logger", "--no-warnings=ExperimentalWarning", "server.mjs"]