Dockerfile: stop baking secrets into the image. Only NODE_ENV remains; all runtime config (MONGO_URI, SMTP_*, token secrets) comes from the environment so one image runs anywhere. Install curl for container healthchecks. App variable names untouched (singular JWT_EXPIRE as read by models/User.js). docker-compose.example.yml: rewrite as a prod run template for git.linuxhg.com/games-database/games-api (IMAGE_TAG, default latest) with restart, env_file .env, and a curl /health healthcheck. Copy to docker-compose.yml next to the server .env, then pull and up. Full variable list kept commented out so values can live in the file instead of .env if preferred.
42 lines
1.4 KiB
Docker
42 lines
1.4 KiB
Docker
# use the official Bun image
|
|
# see all versions at https://hub.docker.com/r/oven/bun/tags
|
|
FROM oven/bun:1 AS base
|
|
WORKDIR /usr/src/app
|
|
|
|
# curl is needed for container healthchecks (curl -f http://localhost:5000/health)
|
|
RUN apt-get update && apt-get install -y --no-install-recommends curl && rm -rf /var/lib/apt/lists/*
|
|
|
|
# install dependencies into temp directory
|
|
# this will cache them and speed up future builds
|
|
FROM base AS install
|
|
RUN mkdir -p /temp/dev
|
|
COPY package.json bun.lockb /temp/dev/
|
|
RUN cd /temp/dev && bun install --frozen-lockfile
|
|
|
|
# install with --production (exclude devDependencies)
|
|
RUN mkdir -p /temp/prod
|
|
COPY package.json bun.lockb /temp/prod/
|
|
RUN cd /temp/prod && bun install --frozen-lockfile --production
|
|
|
|
# copy node_modules from temp directory
|
|
# then copy all (non-ignored) project files into the image
|
|
FROM base AS prerelease
|
|
COPY --from=install /temp/dev/node_modules node_modules
|
|
COPY . .
|
|
|
|
# copy production dependencies and source code into final image
|
|
FROM base AS release
|
|
COPY --from=install /temp/prod/node_modules node_modules
|
|
COPY --from=prerelease /usr/src/app/ .
|
|
COPY --from=prerelease /usr/src/app/package.json .
|
|
|
|
# Runtime config comes from the environment (compose env_file: .env),
|
|
# not baked in at build time, so one image runs anywhere.
|
|
ARG NODE_ENV=production
|
|
ENV NODE_ENV=$NODE_ENV
|
|
|
|
# run the app
|
|
USER bun
|
|
EXPOSE 5000/tcp
|
|
ENTRYPOINT [ "bun", "./bin/www.js" ]
|