SPB Git forge
38commits 1branches 0releases
338.7 MBsize
maindefault branch
3 h agolast push
HTML 53.9% TypeScript 44.5% JavaScript 0.6% SQL 0.5%
3.4 KB · 64 lines
Raw Blame History
1# syntax=docker/dockerfile:1.72# DataCenterIndex — worker image (also runs the scheduler, the migrate one-shot and the `dci` CLI:3# the first CMD word selects the role — see deploy/docker/entrypoint.sh).4# Build context = repo root:  docker build -f deploy/docker/Dockerfile.worker .5ARG NODE_IMAGE=node:22-bookworm-slim6ARG PNPM_VERSION=11.1.27ARG TSX_VERSION=4.23.1389# ---------------------------------------------------------------- base: node + pnpm (build stages only)10FROM ${NODE_IMAGE} AS base11ARG PNPM_VERSION12# pnpm 11 refuses ignored build scripts without a TTY → installs pass --config.dangerously-allow-all-builds=true13# (same setting the laptop uses globally) and --config.confirm-modules-purge=false (prod re-install over `pnpm fetch`).14ENV PNPM_HOME=/pnpm \15    PATH=/pnpm:$PATH \16    npm_config_store_dir=/pnpm/store17RUN (corepack enable && corepack prepare "pnpm@${PNPM_VERSION}" --activate) \18 || npm install -g "pnpm@${PNPM_VERSION}" --no-fund --no-audit1920# ---------------------------------------------------------------- fetch: lockfile-only layer (cached until the lockfile changes)21FROM base AS fetch22WORKDIR /app23COPY pnpm-lock.yaml pnpm-workspace.yaml ./24# pnpm fetch warms the store but also imports EVERY lockfile package into node_modules/.pnpm — drop that so the25# filtered install below only materialises the worker's own dependency graph.26RUN --mount=type=cache,id=dci-pnpm-store,target=/pnpm/store pnpm fetch --prod && rm -rf node_modules2728# ---------------------------------------------------------------- deps: prod install limited to the worker + its workspace deps29FROM fetch AS deps30COPY . .31RUN --mount=type=cache,id=dci-pnpm-store,target=/pnpm/store \32    pnpm install --offline --frozen-lockfile --config.dangerously-allow-all-builds=true --config.confirm-modules-purge=false --prod --filter "@dci/worker..." \33 && rm -rf apps/web apps/api scripts3435# ---------------------------------------------------------------- runtime36FROM ${NODE_IMAGE} AS runtime37ARG TSX_VERSION38ENV NODE_ENV=production \39    NODE_OPTIONS=--enable-source-maps \40    DCI_CONFIG_DIR=/app/config/connectors \41    WORKER_PORT=832042RUN apt-get update \43 && apt-get install -y --no-install-recommends tini ca-certificates \44 && rm -rf /var/lib/apt/lists/* \45 && npm install -g "tsx@${TSX_VERSION}" --no-fund --no-audit \46 && npm cache clean --force47WORKDIR /app48COPY --from=deps --chown=node:node /app/package.json /app/pnpm-workspace.yaml /app/tsconfig.base.json ./49COPY --from=deps --chown=node:node /app/node_modules ./node_modules50COPY --from=deps --chown=node:node /app/packages ./packages51COPY --from=deps --chown=node:node /app/apps/worker ./apps/worker52COPY --from=deps --chown=node:node /app/config ./config53COPY --chown=node:node deploy/docker/ensure-clickhouse.ts ./deploy/docker/ensure-clickhouse.ts54COPY --chmod=755 deploy/docker/entrypoint.sh /usr/local/bin/dci-entrypoint55# `node ../../node_modules/tsx/dist/cli.mjs` (package.json scripts) and the entrypoint both resolve tsx here.56RUN ln -s /usr/local/lib/node_modules/tsx /app/node_modules/tsx \57 && mkdir -p /app/data && chown node:node /app/data58USER node59EXPOSE 832060HEALTHCHECK --interval=30s --timeout=5s --start-period=40s --retries=3 \61  CMD ["node", "-e", "fetch('http://127.0.0.1:'+(process.env.WORKER_PORT||8320)+'/healthz').then(r=>process.exit(r.ok?0:1),()=>process.exit(1))"]62ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/bin/dci-entrypoint"]63CMD ["worker"]64