# Node 24 to match local development: package-lock.json written by a local `npm install` # (npm 11) must also pass `npm ci` here, or the build fails with "lock file out of sync". # 1. Build Stage FROM node:24-alpine AS build WORKDIR /app # Copy dependency files COPY package*.json ./ # Install dependencies RUN npm ci --no-audit --no-fund # Copy source code COPY . . # Build with node-server preset (not cloudflare-module) RUN NITRO_PRESET=node-server npm run build # 2. Production Stage FROM node:24-alpine WORKDIR /app ENV NODE_ENV=production ENV PORT=3000 ENV HOST=0.0.0.0 # The Nitro output is self-contained (dependencies are bundled), so nothing else is copied. COPY --from=build --chown=node:node /app/.output ./.output # Run as the image's unprivileged user rather than root. USER node EXPOSE 3000 # Lets Dokploy/Docker see when the server is actually answering requests. HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \ CMD wget -qO- http://127.0.0.1:3000/ >/dev/null || exit 1 CMD ["node", ".output/server/index.mjs"]