Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
node_modules
build
coverage
.git
.github
.memsearch
.env*
db
data
*.log
1 change: 0 additions & 1 deletion .env.example.compose
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,6 @@ PGPORT=5432 # Local port for postgres - it will always be 5432 inside the contai
JAEGER=jaegertracing/all-in-one:latest

# Fields for App (Required)
APP_COMMAND="npm run start"
PORT=8080
LOG_LEVEL="info"
CORS_ORIGIN="*"
Expand Down
1 change: 0 additions & 1 deletion .env.example.lightnet
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
APP_COMMAND="npm run start"
PORT=8080
LOG_LEVEL="info"
CORS_ORIGIN="*"
Expand Down
27 changes: 20 additions & 7 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,25 +1,38 @@
# Stage 1: Build the TypeScript code
FROM node:20-alpine AS build
# Base image pinned by digest for reproducible, tamper-evident builds (node:20-alpine).
FROM node:20-alpine@sha256:fb4cd12c85ee03686f6af5362a0b0d56d50c58a04632e6c0fb8363f609372293 AS build
WORKDIR /app
COPY package*.json ./
RUN npm ci
COPY src ./src
COPY tsconfig.json ./
RUN npm run build

# Stage 2: Copy the built code and the node modules
FROM node:20-alpine
# Stage 2: Runtime
FROM node:20-alpine@sha256:fb4cd12c85ee03686f6af5362a0b0d56d50c58a04632e6c0fb8363f609372293
WORKDIR /app

# tini as PID 1: forwards SIGTERM to node (so graceful shutdown runs) and reaps zombies.
RUN apk add --no-cache tini

COPY --from=build /app/node_modules ./node_modules
COPY --from=build /app/build ./build
COPY package*.json ./
COPY schema.graphql ./

# Don't run as root
RUN addgroup -g 1001 -S nodejs
RUN adduser -S nodeuser -u 1001
RUN chown -R nodeuser:nodejs /app
RUN addgroup -g 1001 -S nodejs \
&& adduser -S nodeuser -u 1001 \
&& chown -R nodeuser:nodejs /app
USER nodeuser

EXPOSE 8080
CMD ["npm", "start"]

# Liveness check against the built-in endpoint (honours $PORT, defaults to 8080).
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
CMD wget -qO- "http://127.0.0.1:${PORT:-8080}/healthcheck" || exit 1

# Run node directly under tini (not via npm) so the process is a direct child of
# PID 1 and receives signals for graceful shutdown.
ENTRYPOINT ["/sbin/tini", "--"]
CMD ["node", "build/src/index.js"]
1 change: 0 additions & 1 deletion docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,6 @@ services:
restart: always
ports:
- '8080:8080'
command: ${APP_COMMAND}
volumes:
- /app/node_modules
networks:
Expand Down
Loading