Dockerfile 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128
  1. FROM node:22-alpine AS base
  2. RUN apk add --no-cache libc6-compat openssl postgresql-client bash ffmpeg
  3. # Install dependencies only when needed
  4. FROM base AS deps
  5. WORKDIR /app
  6. COPY package.json package-lock.json* ./
  7. COPY prisma ./prisma/
  8. COPY prisma.config.ts ./prisma.config.ts
  9. # npm ci runs the prepare script, which patches next-ws and then applies our
  10. # own follow-up patch from scripts/. The source tree is not copied until the
  11. # builder stage, so that one file has to come along here.
  12. COPY scripts/patch-next-ws-first-upgrade.mjs ./scripts/
  13. RUN npm ci
  14. # Rebuild the source code only when needed
  15. FROM base AS builder
  16. WORKDIR /app
  17. COPY --from=deps /app/node_modules ./node_modules
  18. COPY . .
  19. # Generate Prisma client
  20. RUN npx prisma generate
  21. ENV NEXT_TELEMETRY_DISABLED=1
  22. RUN npm run build
  23. # Production image, copy all the files and run next
  24. FROM base AS runner
  25. WORKDIR /app
  26. ARG APP_VERSION=development
  27. ENV APP_VERSION=${APP_VERSION}
  28. ENV NODE_ENV=production
  29. ENV NEXT_TELEMETRY_DISABLED=1
  30. RUN addgroup --system --gid 1001 nodejs && \
  31. adduser --system --uid 1001 --home /home/nextjs nextjs
  32. # Copy public assets
  33. COPY --from=builder /app/public ./public
  34. # Set correct permissions for prerender cache
  35. RUN mkdir .next && chown nextjs:nodejs .next
  36. # Copy standalone build
  37. COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
  38. COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
  39. # Copy prisma schema and config for migrations
  40. COPY --from=builder --chown=nextjs:nodejs /app/prisma ./prisma
  41. COPY --from=builder --chown=nextjs:nodejs /app/prisma.config.ts ./prisma.config.ts
  42. # Copy generated Prisma client
  43. COPY --from=builder --chown=nextjs:nodejs /app/src/generated ./src/generated
  44. # Give the install below the lockfile the app was built with. Without it npm
  45. # re-resolves the whole tree against the live registry on every build, so the
  46. # runtime image drifts from what was tested, and a registry change can break
  47. # the build with nothing changed here (npm 10 crashed with "Cannot read
  48. # properties of null (reading 'edgesOut')" resolving vitest's peers this way).
  49. COPY --from=builder --chown=nextjs:nodejs /app/package-lock.json ./package-lock.json
  50. # Remove Next.js standalone's traced stubs for pg/prisma (tracer copies package.json
  51. # but not all files), then install the full runtime packages fresh.
  52. RUN rm -rf \
  53. /app/node_modules/pg \
  54. /app/node_modules/pg-types \
  55. /app/node_modules/pg-pool \
  56. /app/node_modules/pg-connection-string \
  57. /app/node_modules/pg-protocol \
  58. /app/node_modules/pg-int8 \
  59. /app/node_modules/pg-cloudflare \
  60. /app/node_modules/pgpass \
  61. /app/node_modules/postgres-array \
  62. /app/node_modules/postgres-bytea \
  63. /app/node_modules/postgres-date \
  64. /app/node_modules/postgres-interval \
  65. /app/node_modules/split2 \
  66. /app/node_modules/prisma \
  67. /app/node_modules/@prisma \
  68. /app/node_modules/.prisma \
  69. && npm install --omit=dev prisma@7.6.0 @prisma/client@7.6.0 @prisma/adapter-pg@7.6.0 pg dotenv tsx sharp
  70. # The npm install above re-resolves the dependency tree and replaces the
  71. # standalone build's PATCHED next package with a fresh unpatched copy from the
  72. # registry, which silently breaks all WebSocket routes (live updates, work
  73. # board sync). Re-apply the next-ws patch so the runtime server can accept
  74. # WebSocket upgrades. next-ws itself is already in the standalone bundle.
  75. #
  76. # sharp is named in that install for the same reason. It is the only native
  77. # module in the tree, its binary lives in a platform-specific optional
  78. # dependency (@img/sharp-linuxmusl-x64 on this image), and re-resolving the
  79. # tree can leave the traced copy without one. Installing it by name makes npm
  80. # resolve the binary against the platform the image will actually run on.
  81. RUN npx next-ws patch --yes
  82. # next-ws reads a route module's exports the moment an upgrade arrives, and
  83. # Next 16.3 loads route modules lazily, so the first WebSocket connection after
  84. # every boot died with "The lazy module is still loading" until the fix below
  85. # is applied to the fresh copy the install above pulled in.
  86. COPY --from=builder --chown=nextjs:nodejs /app/scripts/patch-next-ws-first-upgrade.mjs ./scripts/patch-next-ws-first-upgrade.mjs
  87. RUN node scripts/patch-next-ws-first-upgrade.mjs
  88. # Fail the build here rather than at the first certificate download: a native
  89. # module that cannot be loaded throws while the route module is being
  90. # evaluated, which reaches the browser as an empty HTTP 500 with nothing in it
  91. # to explain itself.
  92. RUN node -e "require('sharp'); console.log('sharp loads')"
  93. # Copy init script
  94. COPY --chown=nextjs:nodejs init-db.sh ./init-db.sh
  95. RUN chmod +x ./init-db.sh
  96. # Create uploads directories
  97. RUN mkdir -p /app/data/uploads && chown -R nextjs:nodejs /app/data
  98. USER nextjs
  99. EXPOSE 3000
  100. ENV PORT=3000
  101. ENV HOSTNAME="0.0.0.0"
  102. ENTRYPOINT ["./init-db.sh"]
  103. CMD ["node", "server.js"]