56 lines
2.1 KiB
Docker
56 lines
2.1 KiB
Docker
# ---------------------------------------------------------------------------
|
|
# @sport/api production image.
|
|
#
|
|
# `turbo prune` produces a subset of the monorepo containing only this app and
|
|
# its workspace dependencies. That keeps the build context small AND makes the
|
|
# Docker layer cache work properly: editing the storefront no longer busts the
|
|
# API's dependency layer.
|
|
# ---------------------------------------------------------------------------
|
|
FROM node:22-alpine AS base
|
|
RUN corepack enable
|
|
WORKDIR /app
|
|
|
|
# --- Stage 1: prune the workspace ------------------------------------------
|
|
FROM base AS pruner
|
|
RUN apk add --no-cache libc6-compat
|
|
COPY . .
|
|
RUN pnpm dlx turbo@2.10.9 prune @sport/api --docker
|
|
|
|
# --- Stage 2: install + build ----------------------------------------------
|
|
FROM base AS builder
|
|
RUN apk add --no-cache libc6-compat openssl
|
|
|
|
# Lockfile and manifests first: this layer is cached until dependencies change.
|
|
COPY --from=pruner /app/out/json/ .
|
|
RUN pnpm install --frozen-lockfile
|
|
|
|
COPY --from=pruner /app/out/full/ .
|
|
RUN pnpm turbo run build --filter=@sport/api
|
|
|
|
# Drop dev dependencies from the tree we are about to copy.
|
|
RUN pnpm prune --prod
|
|
|
|
# --- Stage 3: runtime -------------------------------------------------------
|
|
FROM base AS runner
|
|
RUN apk add --no-cache openssl tini
|
|
|
|
ENV NODE_ENV=production
|
|
|
|
# Never run as root.
|
|
RUN addgroup -g 1001 -S nodejs && adduser -u 1001 -S nestjs -G nodejs
|
|
|
|
COPY --from=builder --chown=nestjs:nodejs /app/node_modules ./node_modules
|
|
COPY --from=builder --chown=nestjs:nodejs /app/packages ./packages
|
|
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/node_modules ./apps/api/node_modules
|
|
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/dist ./apps/api/dist
|
|
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/prisma ./apps/api/prisma
|
|
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/package.json ./apps/api/package.json
|
|
|
|
USER nestjs
|
|
WORKDIR /app/apps/api
|
|
EXPOSE 4000
|
|
|
|
# tini reaps zombies and forwards SIGTERM, so Nest's shutdown hooks actually run.
|
|
ENTRYPOINT ["/sbin/tini", "--"]
|
|
CMD ["node", "dist/main.js"]
|