-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
46 lines (36 loc) · 1.73 KB
/
Copy pathDockerfile
File metadata and controls
46 lines (36 loc) · 1.73 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
# The renderer needs Node at container start (it builds the mounted data/ then
# serves it), so Node has to be in the final image — but npm, the headers and the
# rest of the toolchain do not. Lifting just the binary onto bare Alpine cuts the
# image by ~100 MB.
FROM node:22-alpine AS node
# The build's runtime dependencies (the QR generator), installed here so pnpm
# stays out of the final image too.
FROM node AS deps
WORKDIR /app
COPY package.json pnpm-lock.yaml ./
RUN corepack enable \
&& pnpm install --prod --frozen-lockfile
FROM alpine:3.22
LABEL org.opencontainers.image.title="FrrCard" \
org.opencontainers.image.description="Self-hosted digital business card — one JSON file per person, one static page out." \
org.opencontainers.image.source="https://github.com/FrrCode/FrrCard" \
org.opencontainers.image.licenses="LicenseRef-ISC-Commons-Clause"
# libstdc++ (and the libgcc it pulls in) are all the node binary links against.
RUN apk add --no-cache libstdc++ \
&& addgroup -S -g 1000 node \
&& adduser -S -u 1000 -G node -h /app node
COPY --from=node /usr/local/bin/node /usr/local/bin/node
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY build.js serve.js template.html example.json ./
# data/ and public/ are mounted read-only; dist/ is rebuilt on every start. An
# empty or unmounted data/ falls back to example.json, so a bare `docker run`
# still serves a card.
RUN mkdir -p /app/data /app/public /app/dist && chown node:node /app/dist
ENV PORT=8080 \
NODE_ENV=production
EXPOSE 8080
USER node
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
CMD wget -q --spider "http://127.0.0.1:${PORT}/healthz" || exit 1
CMD ["sh", "-c", "node build.js && exec node serve.js"]