Dockerfile 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117
  1. FROM node:22-alpine AS base
  2. RUN apk add --no-cache libc6-compat openssl postgresql-client bash ffmpeg
  3. # Install dependencies only when needed
  4. FROM base AS deps
  5. WORKDIR /app
  6. COPY package.json package-lock.json* ./
  7. COPY prisma ./prisma/
  8. COPY prisma.config.ts ./prisma.config.ts
  9. RUN npm ci
  10. # Rebuild the source code only when needed
  11. FROM base AS builder
  12. WORKDIR /app
  13. COPY --from=deps /app/node_modules ./node_modules
  14. COPY . .
  15. # Generate Prisma client
  16. RUN npx prisma generate
  17. ENV NEXT_TELEMETRY_DISABLED=1
  18. RUN npm run build
  19. # Production image, copy all the files and run next
  20. FROM base AS runner
  21. WORKDIR /app
  22. ARG APP_VERSION=development
  23. ENV APP_VERSION=${APP_VERSION}
  24. ENV NODE_ENV=production
  25. ENV NEXT_TELEMETRY_DISABLED=1
  26. RUN addgroup --system --gid 1001 nodejs && \
  27. adduser --system --uid 1001 --home /home/nextjs nextjs
  28. # Copy public assets
  29. COPY --from=builder /app/public ./public
  30. # Set correct permissions for prerender cache
  31. RUN mkdir .next && chown nextjs:nodejs .next
  32. # Copy standalone build
  33. COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
  34. COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
  35. # Copy prisma schema and config for migrations
  36. COPY --from=builder --chown=nextjs:nodejs /app/prisma ./prisma
  37. COPY --from=builder --chown=nextjs:nodejs /app/prisma.config.ts ./prisma.config.ts
  38. # Copy generated Prisma client
  39. COPY --from=builder --chown=nextjs:nodejs /app/src/generated ./src/generated
  40. # Give the install below the lockfile the app was built with. Without it npm
  41. # re-resolves the whole tree against the live registry on every build, so the
  42. # runtime image drifts from what was tested, and a registry change can break
  43. # the build with nothing changed here (npm 10 crashed with "Cannot read
  44. # properties of null (reading 'edgesOut')" resolving vitest's peers this way).
  45. COPY --from=builder --chown=nextjs:nodejs /app/package-lock.json ./package-lock.json
  46. # Remove Next.js standalone's traced stubs for pg/prisma (tracer copies package.json
  47. # but not all files), then install the full runtime packages fresh.
  48. RUN rm -rf \
  49. /app/node_modules/pg \
  50. /app/node_modules/pg-types \
  51. /app/node_modules/pg-pool \
  52. /app/node_modules/pg-connection-string \
  53. /app/node_modules/pg-protocol \
  54. /app/node_modules/pg-int8 \
  55. /app/node_modules/pg-cloudflare \
  56. /app/node_modules/pgpass \
  57. /app/node_modules/postgres-array \
  58. /app/node_modules/postgres-bytea \
  59. /app/node_modules/postgres-date \
  60. /app/node_modules/postgres-interval \
  61. /app/node_modules/split2 \
  62. /app/node_modules/prisma \
  63. /app/node_modules/@prisma \
  64. /app/node_modules/.prisma \
  65. && npm install --omit=dev prisma@7.6.0 @prisma/client@7.6.0 @prisma/adapter-pg@7.6.0 pg dotenv tsx sharp
  66. # The npm install above re-resolves the dependency tree and replaces the
  67. # standalone build's PATCHED next package with a fresh unpatched copy from the
  68. # registry, which silently breaks all WebSocket routes (live updates, work
  69. # board sync). Re-apply the next-ws patch so the runtime server can accept
  70. # WebSocket upgrades. next-ws itself is already in the standalone bundle.
  71. #
  72. # sharp is named in that install for the same reason. It is the only native
  73. # module in the tree, its binary lives in a platform-specific optional
  74. # dependency (@img/sharp-linuxmusl-x64 on this image), and re-resolving the
  75. # tree can leave the traced copy without one. Installing it by name makes npm
  76. # resolve the binary against the platform the image will actually run on.
  77. RUN npx next-ws patch --yes
  78. # Fail the build here rather than at the first certificate download: a native
  79. # module that cannot be loaded throws while the route module is being
  80. # evaluated, which reaches the browser as an empty HTTP 500 with nothing in it
  81. # to explain itself.
  82. RUN node -e "require('sharp'); console.log('sharp loads')"
  83. # Copy init script
  84. COPY --chown=nextjs:nodejs init-db.sh ./init-db.sh
  85. RUN chmod +x ./init-db.sh
  86. # Create uploads directories
  87. RUN mkdir -p /app/data/uploads && chown -R nextjs:nodejs /app/data
  88. USER nextjs
  89. EXPOSE 3000
  90. ENV PORT=3000
  91. ENV HOSTNAME="0.0.0.0"
  92. ENTRYPOINT ["./init-db.sh"]
  93. CMD ["node", "server.js"]