-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy pathDockerfile
More file actions
105 lines (86 loc) · 3.84 KB
/
Copy pathDockerfile
File metadata and controls
105 lines (86 loc) · 3.84 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
# syntax=docker/dockerfile:1.7-labs
FROM node:24-slim AS builder
WORKDIR /app
RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates procps git && rm -rf /var/lib/apt/lists/*
ENV NODE_ENV=production
ENV NX_DAEMON=false
ENV NX_PARALLEL=1
ENV NX_ISOLATE_PLUGINS=false
ENV CI=true
ENV HUSKY=0
# Nx Cloud's default CI style only prints a summary + cloud URL. Stream so a
# failed task's tsc/vite output shows up in the GitHub Actions job log.
ENV NX_DEFAULT_OUTPUT_STYLE=stream
# Copy only what pnpm needs to install — no source files.
# patches/ is required because pnpm-workspace.yaml references patch files
# at install time. Workspace package.json files are needed for pnpm to
# resolve the workspace graph.
# ARGs are declared after install so different APP_NAME values across
# parallel matrix jobs share the same cached install layer.
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
COPY patches/ patches/
COPY linting/package.json linting/
COPY apps/platform/package.json apps/platform/
# libs/* are workspace members too — without their manifests pnpm skips the
# per-lib node_modules/@globalfishingwatch/* links a lib needs to import a sibling.
COPY --parents libs/*/package.json ./
ENV PNPM_HOME=/usr/local/share/pnpm
ENV PATH="$PNPM_HOME/bin:$PATH"
RUN SHELL=/bin/sh ENV=/root/.shrc npx --yes get-pnpm 12
RUN pnpm install --frozen-lockfile
# All possible build args — each app uses what it needs, unused ones are empty
ARG APP_NAME
ARG API_GATEWAY
ARG VITE_API_GATEWAY
ARG VITE_API_VERSION
ARG VITE_GOOGLE_MEASUREMENT_ID
ARG VITE_GOOGLE_TAG_MANAGER_ID
ARG PUBLIC_URL
ARG VITE_USE_LOCAL_DATASETS
ARG VITE_USE_LOCAL_DATAVIEWS
ARG VITE_WORKSPACE_ENV
ARG VITE_REPORT_DAYS_LIMIT
ARG VITE_REALTIME_ENABLED
ARG VITE_PIPE_DATASET_VERSION
ARG VITE_PLATFORM_MODE
ARG COMMIT_SHA
ENV API_GATEWAY=$API_GATEWAY \
VITE_API_GATEWAY=$VITE_API_GATEWAY \
VITE_API_VERSION=$VITE_API_VERSION \
VITE_GOOGLE_MEASUREMENT_ID=$VITE_GOOGLE_MEASUREMENT_ID \
VITE_GOOGLE_TAG_MANAGER_ID=$VITE_GOOGLE_TAG_MANAGER_ID \
PUBLIC_URL=$PUBLIC_URL \
VITE_USE_LOCAL_DATASETS=$VITE_USE_LOCAL_DATASETS \
VITE_USE_LOCAL_DATAVIEWS=$VITE_USE_LOCAL_DATAVIEWS \
VITE_WORKSPACE_ENV=$VITE_WORKSPACE_ENV \
VITE_REPORT_DAYS_LIMIT=$VITE_REPORT_DAYS_LIMIT \
VITE_REALTIME_ENABLED=$VITE_REALTIME_ENABLED \
VITE_PIPE_DATASET_VERSION=$VITE_PIPE_DATASET_VERSION \
VITE_PLATFORM_MODE=$VITE_PLATFORM_MODE \
COMMIT_SHA=$COMMIT_SHA
COPY . .
RUN --mount=type=secret,id=NX_CLOUD_ACCESS_TOKEN \
--mount=type=secret,id=SENTRY_AUTH_TOKEN,required=false \
NX_CLOUD_ACCESS_TOKEN="$(cat /run/secrets/NX_CLOUD_ACCESS_TOKEN 2>/dev/null || true)" \
SENTRY_AUTH_TOKEN="$(cat /run/secrets/SENTRY_AUTH_TOKEN 2>/dev/null || true)" \
NODE_OPTIONS='--max-old-space-size=6144' \
pnpm exec nx run ${APP_NAME}:build --output-style=stream
# ── Production: nginx (api-portal, data-download-portal, image-labeler, track-labeler, user-groups-admin) ──
FROM nginx:stable-alpine AS production-nginx
RUN apk update && apk upgrade
ARG APP_NAME
COPY --from=builder /app/dist/apps/${APP_NAME}/nginx.conf /etc/nginx/nginx.template
COPY --from=builder /app/dist/apps/${APP_NAME}/config/entrypoint.sh ./entrypoint.sh
COPY --from=builder /app/dist/apps/${APP_NAME}/ /usr/share/nginx/www/
ENTRYPOINT ["./entrypoint.sh"]
# ── Production: node (platform and future SSR apps) ───────────────────────
FROM node:24-alpine AS production-node
RUN apk update && apk upgrade
WORKDIR /app
ARG APP_NAME=platform
ARG COMMIT_SHA
ARG VITE_WORKSPACE_ENV
ENV SENTRY_RELEASE=$COMMIT_SHA \
SENTRY_ENVIRONMENT=$VITE_WORKSPACE_ENV
COPY --from=builder /app/apps/${APP_NAME}/.output ./output
CMD ["node", "--import", "./output/server/instrument.server.mjs", "--max-http-header-size=40000", "output/server/index.mjs"]