69 lines
2.8 KiB
Docker
69 lines
2.8 KiB
Docker
# ---------- Build-Stage ----------
|
|
# Debian statt Alpine: Prisma 5.x erkennt hier die OpenSSL-3-Engine
|
|
# (debian-openssl-3.0.x) zuverlaessig. Auf aktuellen Alpine-Versionen
|
|
# (OpenSSL >= 3.5) faellt Prisma auf die nicht verfuegbare 1.1-Engine
|
|
# zurueck und der Client kann nicht initialisiert werden.
|
|
FROM node:20-bookworm-slim AS builder
|
|
WORKDIR /app
|
|
ARG HUB_BASE_PATH=""
|
|
ARG MPM_AUTH_MODE="false"
|
|
ENV HUB_BASE_PATH=${HUB_BASE_PATH}
|
|
ENV MPM_AUTH_MODE=${MPM_AUTH_MODE}
|
|
ENV NEXT_PUBLIC_APP_BASE_PATH=${HUB_BASE_PATH}
|
|
|
|
COPY package.json package-lock.json ./
|
|
# ci statt install: reproduzierbarer Build aus dem Lockfile
|
|
RUN npm ci
|
|
|
|
# openssl-Binary: Prisma nutzt es zur Erkennung der Engine-Version.
|
|
# Ohne dieses Binary faellt Prisma auf debian-openssl-1.1.x zurueck,
|
|
# dessen Engine auf Bookworm (OpenSSL 3) nicht ladbar ist.
|
|
RUN apt-get update -y \
|
|
&& apt-get install -y --no-install-recommends openssl \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
COPY prisma ./prisma
|
|
RUN npx prisma generate
|
|
|
|
COPY . .
|
|
RUN npm run build
|
|
|
|
# ---------- Runtime-Stage ----------
|
|
FROM node:20-bookworm-slim AS runner
|
|
WORKDIR /app
|
|
ENV NODE_ENV=production
|
|
ENV HOSTNAME=0.0.0.0
|
|
ENV PORT=3000
|
|
|
|
# openssl auch zur Laufzeit: die Prisma-CLI (migrate deploy) nutzt es
|
|
# zur Engine-Erkennung; ohne Binary sucht sie die 1.1.x-Engine und failt.
|
|
RUN apt-get update -y \
|
|
&& apt-get install -y --no-install-recommends openssl \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN addgroup --system nodejs && adduser --system --ingroup nodejs nextjs
|
|
|
|
COPY --from=builder /app/public ./public
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
|
|
|
|
# Prisma Client inkl. Query-Engine fuer den Laufzeit-Container
|
|
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/.prisma ./node_modules/.prisma
|
|
# Prisma-CLI fuer "migrate deploy" beim Start (kein npx-Download zur Laufzeit)
|
|
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/prisma ./node_modules/prisma
|
|
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/@prisma ./node_modules/@prisma
|
|
COPY --from=builder --chown=nextjs:nodejs /app/prisma ./prisma
|
|
# bcryptjs fuer das Admin-Seed-Script (manuell ausfuehrbar, nicht beim Start)
|
|
COPY --from=builder --chown=nextjs:nodejs /app/node_modules/bcryptjs ./node_modules/bcryptjs
|
|
COPY --from=builder --chown=nextjs:nodejs /app/container-entrypoint.cjs ./container-entrypoint.cjs
|
|
COPY --from=builder --chown=nextjs:nodejs /app/module-runtime.js ./module-runtime.js
|
|
COPY --from=builder --chown=nextjs:nodejs /app/platform-module-sdk.cjs ./platform-module-sdk.cjs
|
|
COPY --from=builder --chown=nextjs:nodejs /app/module.json ./module.json
|
|
|
|
USER nextjs
|
|
EXPOSE 3000 41030
|
|
|
|
# Der gemeinsame Entrypoint setzt die Datenbankverbindung, wendet
|
|
# Migrationen an und startet anschließend Standalone- oder MPM-Betrieb.
|
|
CMD ["node", "container-entrypoint.cjs"]
|