Files
web_sport/infrastructure/docker/api.Dockerfile
T

56 lines
2.1 KiB
Docker

# ---------------------------------------------------------------------------
# @sport/api production image.
#
# `turbo prune` produces a subset of the monorepo containing only this app and
# its workspace dependencies. That keeps the build context small AND makes the
# Docker layer cache work properly: editing the storefront no longer busts the
# API's dependency layer.
# ---------------------------------------------------------------------------
FROM node:22-alpine AS base
RUN corepack enable
WORKDIR /app
# --- Stage 1: prune the workspace ------------------------------------------
FROM base AS pruner
RUN apk add --no-cache libc6-compat
COPY . .
RUN pnpm dlx turbo@2.10.9 prune @sport/api --docker
# --- Stage 2: install + build ----------------------------------------------
FROM base AS builder
RUN apk add --no-cache libc6-compat openssl
# Lockfile and manifests first: this layer is cached until dependencies change.
COPY --from=pruner /app/out/json/ .
RUN pnpm install --frozen-lockfile
COPY --from=pruner /app/out/full/ .
RUN pnpm turbo run build --filter=@sport/api
# Drop dev dependencies from the tree we are about to copy.
RUN pnpm prune --prod
# --- Stage 3: runtime -------------------------------------------------------
FROM base AS runner
RUN apk add --no-cache openssl tini
ENV NODE_ENV=production
# Never run as root.
RUN addgroup -g 1001 -S nodejs && adduser -u 1001 -S nestjs -G nodejs
COPY --from=builder --chown=nestjs:nodejs /app/node_modules ./node_modules
COPY --from=builder --chown=nestjs:nodejs /app/packages ./packages
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/node_modules ./apps/api/node_modules
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/dist ./apps/api/dist
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/prisma ./apps/api/prisma
COPY --from=builder --chown=nestjs:nodejs /app/apps/api/package.json ./apps/api/package.json
USER nestjs
WORKDIR /app/apps/api
EXPOSE 4000
# tini reaps zombies and forwards SIGTERM, so Nest's shutdown hooks actually run.
ENTRYPOINT ["/sbin/tini", "--"]
CMD ["node", "dist/main.js"]