72 lines
2.8 KiB
Docker
72 lines
2.8 KiB
Docker
# Stage 1 — build
|
|
FROM node:22-alpine AS builder
|
|
|
|
WORKDIR /app
|
|
|
|
COPY package*.json ./
|
|
|
|
# `npm ci`, with no `|| npm install` fallback.
|
|
#
|
|
# That fallback was here and it is worse than the error it hides. `npm ci`
|
|
# fails only when package-lock.json disagrees with package.json — exactly the
|
|
# case where falling back to `npm install` resolves fresh versions the lock file
|
|
# never pinned, so the deployed bundle is built from dependencies nobody chose
|
|
# and nobody can reproduce.
|
|
#
|
|
# When this line fails, the fix is `npm install` locally and COMMIT the updated
|
|
# package-lock.json. The build should not paper over a lock file that is out of
|
|
# date; it should say so.
|
|
RUN npm ci --no-audit --no-fund
|
|
|
|
COPY . .
|
|
RUN npm run build
|
|
|
|
# Stage 2 — serve
|
|
FROM nginx:alpine
|
|
|
|
# The config is a TEMPLATE, and that is deliberate.
|
|
#
|
|
# nginx:alpine's entrypoint runs `envsubst` over /etc/nginx/templates/*.template
|
|
# at container start and writes the result into conf.d. That is how the ingest
|
|
# API key reaches nginx as a runtime environment variable rather than being
|
|
# committed here in plain text — which is what the previous Dockerfile did with
|
|
# the Hasura secret, on the line this replaces.
|
|
COPY nginx.conf.template /etc/nginx/templates/default.conf.template
|
|
|
|
# Restricts substitution to this one name.
|
|
#
|
|
# Without the filter, envsubst replaces every `${...}` it recognises as an
|
|
# environment variable — and the container's environment carries HOSTNAME, PATH
|
|
# and friends. Nginx's own `$uri`, `$remote_addr` and `$proxy_add_x_forwarded_for`
|
|
# would survive that today, but only by luck, and a config silently rewritten at
|
|
# boot is a bad thing to leave to luck.
|
|
ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN
|
|
|
|
# Empty by default — and this line is LOAD-BEARING. Do not delete it.
|
|
#
|
|
# BuildKit warns about it: `SecretsUsedInArgOrEnv: Do not use ARG or ENV
|
|
# instructions for sensitive data (ENV "INGEST_TOKEN")`. The warning is right in
|
|
# general and wrong here: nothing sensitive is baked in, the value is the empty
|
|
# string, and the real token is supplied at RUN time by the deployment.
|
|
#
|
|
# Removing the line to silence the warning breaks the config in a way that is
|
|
# hard to see. nginx's entrypoint builds its substitution list from env vars
|
|
# that are DEFINED:
|
|
#
|
|
# defined_envs=$(printf '${%s} ' $(awk "END { for (name in ENVIRON) ... }"))
|
|
#
|
|
# With INGEST_TOKEN undefined, it is not in that list, envsubst leaves the
|
|
# placeholder alone, and nginx ends up with the literal text `${INGEST_TOKEN}`
|
|
# as the token — which is not empty, so the missing-token guard never fires and
|
|
# every ingest call goes out with a nonsense `X-API-Key`.
|
|
#
|
|
# Declaring it empty here guarantees envsubst always substitutes it, so an
|
|
# unset token is a real empty string and the guard can catch it.
|
|
ENV INGEST_TOKEN=""
|
|
|
|
COPY --from=builder /app/dist/ /usr/share/nginx/html/
|
|
|
|
EXPOSE 80
|
|
|
|
CMD ["nginx", "-g", "daemon off;"]
|