# ---- Build stage ---- FROM node:22-alpine AS build WORKDIR /app # Safety valve for the 2 GB host: without a cap a runaway build can exhaust the # server's RAM and take down neighbouring containers. Measured peak for this app # is ~550 MB, so 1 GB leaves headroom while still failing the build rather than # the server. Raise this only if the host gets more RAM. ENV NODE_OPTIONS=--max-old-space-size=1024 # Install deps from the lockfile first so this layer is reused when only src changes COPY package.json package-lock.json ./ RUN npm ci --no-audit --no-fund COPY . . # The API origin, baked into the bundle at build time. # # Vite inlines VITE_* variables during `npm run build`; there is no runtime # configuration for a static bundle. It has to be an environment variable here # because .dockerignore excludes .env*, so no env file ever reaches this stage — # and without a value the client falls back to a relative /api/v1, which the # nginx runtime stage below serves as a static path. That answers a login POST # with 405 Method Not Allowed, because static file serving permits only # GET/HEAD. # # It must include the /api/v1 suffix: httpClient.js builds each URL as # `${API_BASE_URL}${path}` where path is `/auth/login`. # # Override per environment with: # docker build --build-arg VITE_API_BASE_URL=https://other.example.com/api/v1 . ARG VITE_API_BASE_URL=https://mcp.krowforce.com/api/v1 ENV VITE_API_BASE_URL=$VITE_API_BASE_URL RUN npm run build # ---- Runtime stage ---- FROM nginx:alpine # Remove Nginx's default "Welcome" page files completely RUN rm -rf /usr/share/nginx/html/* # Only the compiled assets reach the final image — no node_modules, no source COPY --from=build /app/dist /usr/share/nginx/html COPY nginx.conf /etc/nginx/nginx.conf EXPOSE 80 3000 CMD ["nginx", "-g", "daemon off;"]