# Stage 1 — build FROM node:22-alpine AS builder WORKDIR /app COPY package*.json ./ # `npm ci`, with no `|| npm install` fallback. # # That fallback was here and it is worse than the error it hides. `npm ci` # fails only when package-lock.json disagrees with package.json — exactly the # case where falling back to `npm install` resolves fresh versions the lock file # never pinned, so the deployed bundle is built from dependencies nobody chose # and nobody can reproduce. # # When this line fails, the fix is to update package-lock.json locally and # COMMIT it. The build should not paper over a lock file that is out of date; # it should say so. # # ── But `npm install` alone is how the lock got broken once ───────────────── # # This image is node:22-alpine, which ships npm 10.9.8. A developer on npm 11 # running `npm install` rewrites the lock in a shape npm 10 rejects: npm 11 # prunes optional platform packages that npm 10 still validates. Adding leaflet # on npm 11.6.2 dropped `@emnapi/core` and `@emnapi/runtime` — transitive # optional deps of `@tailwindcss/oxide-wasm32-wasi` — and the next deploy died # here with "Missing: @emnapi/core@1.11.3 from lock file". Nothing was wrong # with the code; the lock was genuinely incomplete and this line was right to # refuse it. # # So after changing dependencies, prove the lock against THIS npm before # pushing, in a scratch directory so node_modules is not disturbed: # # mkdir /tmp/lockcheck && cp package.json package-lock.json /tmp/lockcheck/ # cd /tmp/lockcheck && npx npm@10.9.8 ci # # and if it fails, regenerate with the same version: # # npx npm@10.9.8 install --package-lock-only RUN npm ci --no-audit --no-fund COPY . . # Where the bundle points at the backend, fixed HERE rather than left to `.env`. # # Deployment platforms write their own `.env` into the source directory before # building — Dokploy does — which overwrites the committed one and takes # VITE_API_BASE with it. The build then fell through to a same-origin path and # the console called `https:///fiesta/live/api/...`. A build # argument outranks the file, so the host survives that overwrite. # # Override per environment with `--build-arg VITE_API_BASE=...` (Dokploy: Build # Args), e.g. to point a staging console at a staging Fiesta. ARG VITE_API_BASE="https://fiesta.nearle.app" ENV VITE_API_BASE=$VITE_API_BASE # Which console this image is. # # platform → platform.nearledaily.com, Nearle's own staff # merchant → app.nearledaily.com, merchants and their branch users # # The same source builds both. What the flag changes is which workspace's routes # are mounted and which roles may sign in — neither image lets the other's # accounts through. Both images still CONTAIN both workspaces' compiled chunks; # the unmounted one is never fetched because nothing routes to it. # # Defaulting to `merchant` keeps every existing deployment behaving exactly as # it did. The platform build is the one that has to be asked for — the opposite # default would turn every environment that had not been told about this into a # platform console on the day it shipped. # There is no workspace flag in this image. # # One existed while a single codebase served both consoles and had to be told # which it was. Nearle's own staff now have their own application — # `nearle-platform`, its own repository and its own deploy — and this image is # the merchant console and nothing else. # # The platform console's address, for the sentence shown to a staff member who # signs in at the wrong site. A build argument rather than a constant because # the two are separate deployments and either can move. ARG VITE_PLATFORM_HOST="platform.nearledaily.com" ENV VITE_PLATFORM_HOST=$VITE_PLATFORM_HOST RUN npm run build # Stage 2 — serve FROM nginx:alpine # The config is a TEMPLATE, and that is deliberate. # # nginx:alpine's entrypoint runs `envsubst` over /etc/nginx/templates/*.template # at container start and writes the result into conf.d. That is how the ingest # API key reaches nginx as a runtime environment variable rather than being # committed here in plain text — which is what the previous Dockerfile did with # the Hasura secret, on the line this replaces. COPY nginx.conf.template /etc/nginx/templates/default.conf.template # Restricts substitution to this one name. # # Without the filter, envsubst replaces every `${...}` it recognises as an # environment variable — and the container's environment carries HOSTNAME, PATH # and friends. Nginx's own `$uri`, `$remote_addr` and `$proxy_add_x_forwarded_for` # would survive that today, but only by luck, and a config silently rewritten at # boot is a bad thing to leave to luck. ENV NGINX_ENVSUBST_FILTER="(INGEST_TOKEN|INGEST_UPSTREAM)" # Empty by default — and this line is LOAD-BEARING. Do not delete it. # # BuildKit warns about it: `SecretsUsedInArgOrEnv: Do not use ARG or ENV # instructions for sensitive data (ENV "INGEST_TOKEN")`. The warning is right in # general and wrong here: nothing sensitive is baked in, the value is the empty # string, and the real token is supplied at RUN time by the deployment. # # Removing the line to silence the warning breaks the config in a way that is # hard to see. nginx's entrypoint builds its substitution list from env vars # that are DEFINED: # # defined_envs=$(printf '${%s} ' $(awk "END { for (name in ENVIRON) ... }")) # # With INGEST_TOKEN undefined, it is not in that list, envsubst leaves the # placeholder alone, and nginx ends up with the literal text `${INGEST_TOKEN}` # as the token — which is not empty, so the missing-token guard never fires and # every ingest call goes out with a nonsense `X-API-Key`. # # Declaring it empty here guarantees envsubst always substitutes it, so an # unset token is a real empty string and the guard can catch it. ENV INGEST_TOKEN="" # Where the ingest service is. Declared here for the same reason as the line # above: envsubst only substitutes names that are DEFINED, so an undeclared # INGEST_UPSTREAM would leave the literal text `${INGEST_UPSTREAM}` in the # config as the proxy target, and nginx would fail to start with an error that # names the variable rather than the omission. # # Defaults to the public host so an existing deployment behaves exactly as it # did. Set it to the sibling container's internal address — e.g. # `http://mcp-backend:8000` — to take the private path and drop the credential # entirely. ENV INGEST_UPSTREAM="https://mcp.nearle.ai.in" COPY --from=builder /app/dist/ /usr/share/nginx/html/ EXPOSE 80 3000 CMD ["nginx", "-g", "daemon off;"]