batchCooking/apps/api/Dockerfile
kyuno053 bc582b75d6
Add Docker packaging for local functional review (api + web) (#5)
apps/api/Dockerfile: multi-stage build on node:22-slim (not alpine —
avoids musl-vs-glibc native binding surprises for argon2/Prisma's
engine binaries; same base image family for build and runtime stages
keeps "native" binaries compatible across stages). Runtime stage
copies the monorepo structure as-is rather than flattening to a single
package, so pnpm's symlinked node_modules stay valid. Container runs
`prisma migrate deploy` on startup before starting the server, so the
review environment's schema is always in sync automatically.

Installs openssl explicitly in the base image: without it, Prisma
can't detect the right engine binary and silently defaults to a guess
that may not match what's actually on the image — caught by checking
the build log, not just a successful build.

apps/web/Dockerfile: builds with Vite, serves the static output via
nginx (not a Node static server) — avoids the devDependency problem of
needing `vite preview` in a --prod-deployed image, and is the more
standard way to serve a built SPA. nginx.conf has an SPA fallback
(try_files ... /index.html) ready for when client-side routing lands.

docker-compose.yml: adds `api` and `web` services alongside the
existing `postgres`. api's DATABASE_URL targets the `postgres` service
name over the compose network (not localhost/POSTGRES_PORT, which is
only the host-side mapping). Both new services require JWT_SECRET/
ports via env vars with no defaults, consistent with the project's
existing no-hardcoded-credentials rule.

.dockerignore added — without it, the Windows-built node_modules
(with Windows-specific native binaries) would get copied into the
Linux build context.

Verified: full build (api + web images), `docker compose up -d`
brought up all three containers, curled /health and the web root,
ran a real signup through the containerized stack end-to-end.
2026-08-16 14:13:51 +02:00

36 lines
1.7 KiB
Docker

# Debian-based (not alpine) on purpose: avoids musl-vs-glibc native binding
# surprises for argon2/Prisma's engine binaries. Same base image family for
# build and runtime stages, so "native" binaries built in `build` are
# guaranteed compatible with `runtime`.
FROM node:22-slim AS base
# Prisma's query engine needs OpenSSL to be present to detect the right
# binary target; without it, it silently defaults to a guess (openssl-1.1.x)
# that may not match what's actually on the image and fail at runtime.
RUN apt-get update && apt-get install -y --no-install-recommends openssl && rm -rf /var/lib/apt/lists/*
RUN corepack enable
WORKDIR /repo
FROM base AS build
COPY . .
RUN pnpm install --frozen-lockfile
RUN pnpm --filter api build
# Copies the monorepo structure as-is (not a flattened single package) so
# pnpm's symlinked node_modules (root node_modules/.pnpm <- apps/api/node_modules)
# stay valid — paths must match exactly between build and runtime stages.
FROM base AS runtime
ENV NODE_ENV=production
COPY --from=build /repo/node_modules ./node_modules
COPY --from=build /repo/package.json ./package.json
COPY --from=build /repo/pnpm-workspace.yaml ./pnpm-workspace.yaml
COPY --from=build /repo/packages/shared ./packages/shared
COPY --from=build /repo/apps/api/node_modules ./apps/api/node_modules
COPY --from=build /repo/apps/api/dist ./apps/api/dist
COPY --from=build /repo/apps/api/prisma ./apps/api/prisma
COPY --from=build /repo/apps/api/package.json ./apps/api/package.json
WORKDIR /repo/apps/api
EXPOSE 3000
# Applies pending migrations before starting — keeps the review environment's
# schema in sync automatically, no manual step needed.
CMD ["sh", "-c", "node_modules/.bin/prisma migrate deploy && node dist/server.js"]