# Stage 1 — build FROM node:22-alpine AS builder WORKDIR /app COPY package*.json ./ # `npm ci`, with no `|| npm install` fallback. # # That fallback was here and it is worse than the error it hides. `npm ci` # fails only when package-lock.json disagrees with package.json — exactly the # case where falling back to `npm install` resolves fresh versions the lock file # never pinned, so the deployed bundle is built from dependencies nobody chose # and nobody can reproduce. # # When this line fails, the fix is `npm install` locally and COMMIT the updated # package-lock.json. The build should not paper over a lock file that is out of # date; it should say so. RUN npm ci --no-audit --no-fund COPY . . RUN npm run build # Stage 2 — serve FROM nginx:alpine # The config is a TEMPLATE, and that is deliberate. # # nginx:alpine's entrypoint runs `envsubst` over /etc/nginx/templates/*.template # at container start and writes the result into conf.d. That is how the ingest # API key reaches nginx as a runtime environment variable rather than being # committed here in plain text — which is what the previous Dockerfile did with # the Hasura secret, on the line this replaces. COPY nginx.conf.template /etc/nginx/templates/default.conf.template # Restricts substitution to this one name. # # Without the filter, envsubst replaces every `${...}` it recognises as an # environment variable — and the container's environment carries HOSTNAME, PATH # and friends. Nginx's own `$uri`, `$remote_addr` and `$proxy_add_x_forwarded_for` # would survive that today, but only by luck, and a config silently rewritten at # boot is a bad thing to leave to luck. ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN # Empty by default, so the image runs without it. Sheet upload then fails with # the ingest service's own 401, which says what is missing — rather than nginx # refusing to start and taking the whole console down with it. ENV INGEST_TOKEN="" COPY --from=builder /app/dist/ /usr/share/nginx/html/ EXPOSE 80 CMD ["nginx", "-g", "daemon off;"]