initial commit
This commit is contained in:
131
Dockerfile
Normal file
131
Dockerfile
Normal file
@@ -0,0 +1,131 @@
|
||||
# Stage 1 — build
|
||||
FROM node:22-alpine AS builder
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY package*.json ./
|
||||
|
||||
# `npm ci`, with no `|| npm install` fallback.
|
||||
#
|
||||
# That fallback was here and it is worse than the error it hides. `npm ci`
|
||||
# fails only when package-lock.json disagrees with package.json — exactly the
|
||||
# case where falling back to `npm install` resolves fresh versions the lock file
|
||||
# never pinned, so the deployed bundle is built from dependencies nobody chose
|
||||
# and nobody can reproduce.
|
||||
#
|
||||
# When this line fails, the fix is to update package-lock.json locally and
|
||||
# COMMIT it. The build should not paper over a lock file that is out of date;
|
||||
# it should say so.
|
||||
#
|
||||
# ── But `npm install` alone is how the lock got broken once ─────────────────
|
||||
#
|
||||
# This image is node:22-alpine, which ships npm 10.9.8. A developer on npm 11
|
||||
# running `npm install` rewrites the lock in a shape npm 10 rejects: npm 11
|
||||
# prunes optional platform packages that npm 10 still validates. Adding leaflet
|
||||
# on npm 11.6.2 dropped `@emnapi/core` and `@emnapi/runtime` — transitive
|
||||
# optional deps of `@tailwindcss/oxide-wasm32-wasi` — and the next deploy died
|
||||
# here with "Missing: @emnapi/core@1.11.3 from lock file". Nothing was wrong
|
||||
# with the code; the lock was genuinely incomplete and this line was right to
|
||||
# refuse it.
|
||||
#
|
||||
# So after changing dependencies, prove the lock against THIS npm before
|
||||
# pushing, in a scratch directory so node_modules is not disturbed:
|
||||
#
|
||||
# mkdir /tmp/lockcheck && cp package.json package-lock.json /tmp/lockcheck/
|
||||
# cd /tmp/lockcheck && npx npm@10.9.8 ci
|
||||
#
|
||||
# and if it fails, regenerate with the same version:
|
||||
#
|
||||
# npx npm@10.9.8 install --package-lock-only
|
||||
RUN npm ci --no-audit --no-fund
|
||||
|
||||
COPY . .
|
||||
|
||||
# Where the bundle points at the backend, fixed HERE rather than left to `.env`.
|
||||
#
|
||||
# Deployment platforms write their own `.env` into the source directory before
|
||||
# building — Dokploy does — which overwrites the committed one and takes
|
||||
# VITE_API_BASE with it. The build then fell through to a same-origin path and
|
||||
# the console called `https://<its own domain>/fiesta/live/api/...`. A build
|
||||
# argument outranks the file, so the host survives that overwrite.
|
||||
#
|
||||
# Override per environment with `--build-arg VITE_API_BASE=...` (Dokploy: Build
|
||||
# Args), e.g. to point a staging console at a staging Fiesta.
|
||||
ARG VITE_API_BASE="https://fiesta.nearle.app"
|
||||
ENV VITE_API_BASE=$VITE_API_BASE
|
||||
|
||||
# There is no workspace flag in this image.
|
||||
#
|
||||
# This repository IS the Nearle platform console — every route it mounts is the
|
||||
# platform workspace and only Nearle staff can sign in. The merchant console is
|
||||
# a separate repository with its own deploy. A flag here would exist only as a
|
||||
# way to deploy this application as something it is not.
|
||||
#
|
||||
# The merchant console's address, for the sentence shown to a merchant who
|
||||
# signs in at the wrong site. A build argument rather than a constant because
|
||||
# the two are separate deployments and either can move.
|
||||
ARG VITE_MERCHANT_HOST="app.nearledaily.com"
|
||||
ENV VITE_MERCHANT_HOST=$VITE_MERCHANT_HOST
|
||||
|
||||
RUN npm run build
|
||||
|
||||
# Stage 2 — serve
|
||||
FROM nginx:alpine
|
||||
|
||||
# The config is a TEMPLATE, and that is deliberate.
|
||||
#
|
||||
# nginx:alpine's entrypoint runs `envsubst` over /etc/nginx/templates/*.template
|
||||
# at container start and writes the result into conf.d. That is how the ingest
|
||||
# API key reaches nginx as a runtime environment variable rather than being
|
||||
# committed here in plain text — which is what the previous Dockerfile did with
|
||||
# the Hasura secret, on the line this replaces.
|
||||
COPY nginx.conf.template /etc/nginx/templates/default.conf.template
|
||||
|
||||
# Restricts substitution to this one name.
|
||||
#
|
||||
# Without the filter, envsubst replaces every `${...}` it recognises as an
|
||||
# environment variable — and the container's environment carries HOSTNAME, PATH
|
||||
# and friends. Nginx's own `$uri`, `$remote_addr` and `$proxy_add_x_forwarded_for`
|
||||
# would survive that today, but only by luck, and a config silently rewritten at
|
||||
# boot is a bad thing to leave to luck.
|
||||
ENV NGINX_ENVSUBST_FILTER="(INGEST_TOKEN|INGEST_UPSTREAM)"
|
||||
|
||||
# Empty by default — and this line is LOAD-BEARING. Do not delete it.
|
||||
#
|
||||
# BuildKit warns about it: `SecretsUsedInArgOrEnv: Do not use ARG or ENV
|
||||
# instructions for sensitive data (ENV "INGEST_TOKEN")`. The warning is right in
|
||||
# general and wrong here: nothing sensitive is baked in, the value is the empty
|
||||
# string, and the real token is supplied at RUN time by the deployment.
|
||||
#
|
||||
# Removing the line to silence the warning breaks the config in a way that is
|
||||
# hard to see. nginx's entrypoint builds its substitution list from env vars
|
||||
# that are DEFINED:
|
||||
#
|
||||
# defined_envs=$(printf '${%s} ' $(awk "END { for (name in ENVIRON) ... }"))
|
||||
#
|
||||
# With INGEST_TOKEN undefined, it is not in that list, envsubst leaves the
|
||||
# placeholder alone, and nginx ends up with the literal text `${INGEST_TOKEN}`
|
||||
# as the token — which is not empty, so the missing-token guard never fires and
|
||||
# every ingest call goes out with a nonsense `X-API-Key`.
|
||||
#
|
||||
# Declaring it empty here guarantees envsubst always substitutes it, so an
|
||||
# unset token is a real empty string and the guard can catch it.
|
||||
ENV INGEST_TOKEN=""
|
||||
|
||||
# Where the ingest service is. Declared here for the same reason as the line
|
||||
# above: envsubst only substitutes names that are DEFINED, so an undeclared
|
||||
# INGEST_UPSTREAM would leave the literal text `${INGEST_UPSTREAM}` in the
|
||||
# config as the proxy target, and nginx would fail to start with an error that
|
||||
# names the variable rather than the omission.
|
||||
#
|
||||
# Defaults to the public host so an existing deployment behaves exactly as it
|
||||
# did. Set it to the sibling container's internal address — e.g.
|
||||
# `http://mcp-backend:8000` — to take the private path and drop the credential
|
||||
# entirely.
|
||||
ENV INGEST_UPSTREAM="https://mcp.nearle.ai.in"
|
||||
|
||||
COPY --from=builder /app/dist/ /usr/share/nginx/html/
|
||||
|
||||
EXPOSE 80 3000
|
||||
|
||||
CMD ["nginx", "-g", "daemon off;"]
|
||||
Reference in New Issue
Block a user