nginx fix
This commit is contained in:
44
Dockerfile
44
Dockerfile
@@ -1,37 +1,41 @@
|
||||
# Stage 1: Build the React application
|
||||
# Stage 1 — build
|
||||
FROM node:22-alpine AS builder
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Copy package.json and lockfile
|
||||
COPY package*.json ./
|
||||
RUN npm ci || npm install
|
||||
|
||||
# Install dependencies
|
||||
RUN npm install
|
||||
|
||||
# Copy the rest of your application code
|
||||
COPY . .
|
||||
|
||||
# Build the Vite application (this creates the /app/dist folder inside the container)
|
||||
RUN npm run build
|
||||
|
||||
# Stage 2: Serve the application with Nginx
|
||||
# Stage 2 — serve
|
||||
FROM nginx:alpine
|
||||
|
||||
# Set the default Hasura admin secret (can be overridden at runtime)
|
||||
ENV HASURA_ADMIN_SECRET="nearle-admin-secret"
|
||||
# The config is a TEMPLATE, and that is deliberate.
|
||||
#
|
||||
# nginx:alpine's entrypoint runs `envsubst` over /etc/nginx/templates/*.template
|
||||
# at container start and writes the result into conf.d. That is how the ingest
|
||||
# API key reaches nginx as a runtime environment variable rather than being
|
||||
# committed here in plain text — which is what the previous Dockerfile did with
|
||||
# the Hasura secret, on the line this replaces.
|
||||
COPY nginx.conf.template /etc/nginx/templates/default.conf.template
|
||||
|
||||
# Move to Nginx's public folder
|
||||
WORKDIR /usr/share/nginx/html
|
||||
# Restricts substitution to this one name.
|
||||
#
|
||||
# Without the filter, envsubst replaces every `${...}` it recognises as an
|
||||
# environment variable — and the container's environment carries HOSTNAME, PATH
|
||||
# and friends. Nginx's own `$uri`, `$remote_addr` and `$proxy_add_x_forwarded_for`
|
||||
# would survive that today, but only by luck, and a config silently rewritten at
|
||||
# boot is a bad thing to leave to luck.
|
||||
ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN
|
||||
|
||||
# CRUCIAL: Remove Nginx's default "Welcome" page files completely
|
||||
RUN rm -rf ./*
|
||||
# Empty by default, so the image runs without it. Sheet upload then fails with
|
||||
# the ingest service's own 401, which says what is missing — rather than nginx
|
||||
# refusing to start and taking the whole console down with it.
|
||||
ENV INGEST_TOKEN=""
|
||||
|
||||
# Copy the compiled static assets FROM THE BUILDER STAGE
|
||||
COPY --from=builder /app/dist/ .
|
||||
|
||||
# Copy your custom Nginx configuration into the conf.d directory so it gets included properly
|
||||
COPY nginx.conf /etc/nginx/conf.d/default.conf
|
||||
COPY --from=builder /app/dist/ /usr/share/nginx/html/
|
||||
|
||||
EXPOSE 80
|
||||
|
||||
|
||||
Reference in New Issue
Block a user