feat: Add Docker Compose setup for frontend, backend, and MongoDB - #223
Vinayak097 wants to merge 3 commits into
Conversation
📝 WalkthroughWalkthroughAdds Docker support to the MERN stack project: new Dockerfiles for the client (port 3000) and server (port 5000), ChangesDocker Containerization
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@client/Dockerfile`:
- Around line 1-13: Both the client/Dockerfile (lines 1-13) and
server/Dockerfile (lines 1-13) are running containers as root due to missing
USER directives, creating a security vulnerability. For each file, after the
COPY instruction that copies the application files, add a RUN instruction to
change ownership of the /app directory using chown command (chown -R node:node
/app), then add a USER node directive before the CMD instruction to ensure the
container runs as the non-root node user instead of root.
In `@docker-compose.yml`:
- Around line 13-14: The depends_on section using the short form only ensures
MongoDB container starts but does not wait for it to be healthy and ready to
accept connections. Replace the short form depends_on with the expanded form
that includes a condition parameter set to service_healthy, which will make the
backend service wait for MongoDB to pass its health check before attempting to
start. This requires that the mongodb service has a healthcheck defined in its
configuration.
In `@server/index.js`:
- Line 17: The CONNECTION_URL constant is hardcoded with the MongoDB hostname
instead of using the environment variable from docker-compose.yml. Replace the
hardcoded string value 'mongodb://mongodb:27017/memories' with
process.env.CONNECTION_URL to use the environment variable passed from Compose,
which ensures the connection works in both Docker and non-Docker environments.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 87cfdb3d-4ce8-4390-bd07-799e979f205b
⛔ Files ignored due to path filters (2)
client/package-lock.jsonis excluded by!**/package-lock.jsonserver/package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (8)
client/.dockerignoreclient/Dockerfileclient/package.jsondocker-compose.ymlserver/.dockerignoreserver/Dockerfileserver/index.jsserver/package.json
| FROM node:18-alpine | ||
|
|
||
| WORKDIR /app | ||
|
|
||
| COPY package*.json ./ | ||
|
|
||
| RUN npm install | ||
|
|
||
| COPY . . | ||
|
|
||
| EXPOSE 3000 | ||
|
|
||
| CMD ["npm","start"] No newline at end of file |
There was a problem hiding this comment.
Both Docker images run as root at runtime due the same missing USER directive.
This is one shared security posture gap across both service images.
client/Dockerfile#L1-L13: after copying sources, switch ownership and setUSER nodebeforeCMD.server/Dockerfile#L1-L13: apply the same non-root runtime pattern (chown+USER node) beforeCMD.
🧰 Tools
🪛 Trivy (0.69.3)
[error] 1-1: Image user should not be 'root'
Specify at least 1 USER command in Dockerfile with non-root user as argument
Rule: DS-0002
(IaC/Dockerfile)
📍 Affects 2 files
client/Dockerfile#L1-L13(this comment)server/Dockerfile#L1-L13
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@client/Dockerfile` around lines 1 - 13, Both the client/Dockerfile (lines
1-13) and server/Dockerfile (lines 1-13) are running containers as root due to
missing USER directives, creating a security vulnerability. For each file, after
the COPY instruction that copies the application files, add a RUN instruction to
change ownership of the /app directory using chown command (chown -R node:node
/app), then add a USER node directive before the CMD instruction to ensure the
container runs as the non-root node user instead of root.
Source: Linters/SAST tools
| depends_on: | ||
| - mongodb |
There was a problem hiding this comment.
Gate backend startup on MongoDB health, not only startup order.
Line 13/Line 14 use short depends_on, which does not wait for MongoDB readiness. This can race the server boot and cause failed initial connections.
Suggested fix
services:
mongodb:
image: mongo:7
ports:
- "27017:27017"
volumes:
- mongo_data:/data/db
+ healthcheck:
+ test: ["CMD", "mongosh", "--eval", "db.adminCommand('ping')"]
+ interval: 10s
+ timeout: 5s
+ retries: 5
server:
build: ./server
ports:
- "5000:5000"
depends_on:
- - mongodb
+ mongodb:
+ condition: service_healthy📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| depends_on: | |
| - mongodb | |
| services: | |
| mongodb: | |
| image: mongo:7 | |
| ports: | |
| - "27017:27017" | |
| volumes: | |
| - mongo_data:/data/db | |
| healthcheck: | |
| test: ["CMD", "mongosh", "--eval", "db.adminCommand('ping')"] | |
| interval: 10s | |
| timeout: 5s | |
| retries: 5 | |
| server: | |
| build: ./server | |
| ports: | |
| - "5000:5000" | |
| depends_on: | |
| mongodb: | |
| condition: service_healthy |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@docker-compose.yml` around lines 13 - 14, The depends_on section using the
short form only ensures MongoDB container starts but does not wait for it to be
healthy and ready to accept connections. Replace the short form depends_on with
the expanded form that includes a condition parameter set to service_healthy,
which will make the backend service wait for MongoDB to pass its health check
before attempting to start. This requires that the mongodb service has a
healthcheck defined in its configuration.
| app.use('/posts', postRoutes); | ||
|
|
||
| const CONNECTION_URL = 'mongodb+srv://js_mastery:123123123@practice.jto9p.mongodb.net/test'; | ||
| const CONNECTION_URL = 'mongodb://mongodb:27017/memories'; |
There was a problem hiding this comment.
Use process.env.CONNECTION_URL instead of hardcoding the Compose hostname.
Line 17 hardcodes mongodb and ignores the environment variable passed from Compose (docker-compose.yml, Line 16). This also breaks non-Docker runs where mongodb DNS does not exist.
Suggested fix
-const CONNECTION_URL = 'mongodb://mongodb:27017/memories';
+const CONNECTION_URL = process.env.CONNECTION_URL || 'mongodb://localhost:27017/memories';📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| const CONNECTION_URL = 'mongodb://mongodb:27017/memories'; | |
| const CONNECTION_URL = process.env.CONNECTION_URL || 'mongodb://localhost:27017/memories'; |
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@server/index.js` at line 17, The CONNECTION_URL constant is hardcoded with
the MongoDB hostname instead of using the environment variable from
docker-compose.yml. Replace the hardcoded string value
'mongodb://mongodb:27017/memories' with process.env.CONNECTION_URL to use the
environment variable passed from Compose, which ensures the connection works in
both Docker and non-Docker environments.
Summary
This PR adds Docker support to the project, allowing the frontend, backend, and MongoDB database to run in separate containers using Docker Compose.
Changes
How to Run
Frontend: http://localhost:3000/
Backend: http://localhost:5000/
MongoDB: mongodb://localhost:27017
Related Issue
Closes #217
Summary by CodeRabbit