bf632d90a5
- WR-01: prisma generate als eigener Schritt mit Pruefung im api-Abbild, Bau scheitert ohne Client; Startprobe als .gitea/scripts/image-start-check.sh versioniert - WR-02: Semgrep im offiziellen Container, per Digest angepinnt (kein pipx/PyPI mehr) - WR-04: Zeitbudget 1500 s, Limits je Werkzeug, Ergebniszeile sofort nach jedem Werkzeug - WR-05: Authorization-Ersetzung der ZAP-Pruefung nur fuer das Ziel - IN-01: yarn/npm per Platzhalter entfernt und Abwesenheit geprueft (api und web) - IN-02: Kommentar zu doppelten Kopfzeilen in next.config.ts richtiggestellt - IN-03: Berichtsordner Modus 700, Zugangsdaten nur als base64 (keine curl-Konfiguration) - IN-04: flacher Klon wird bei gitleaks als unvollstaendig gemeldet Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
65 lines
2.8 KiB
Docker
65 lines
2.8 KiB
Docker
# Versionsstempel (quick-260914-ku1): die Werte setzt .gitea/scripts/publish-images.sh
|
|
# per --build-arg; lokal greifen die Vorgaben (dev). Ein globales ARG liefert nur die
|
|
# Vorgabe -- jede nutzende Stufe wiederholt deshalb `ARG NAME` ohne Wert.
|
|
ARG APP_VERSION=dev
|
|
ARG APP_CHANNEL=dev
|
|
ARG APP_COMMIT=
|
|
ARG APP_BUILD_TIME=
|
|
|
|
FROM node:24-alpine AS base
|
|
RUN corepack enable && corepack prepare pnpm@9 --activate
|
|
|
|
FROM base AS deps
|
|
WORKDIR /app
|
|
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
|
|
COPY apps/web/package.json ./apps/web/
|
|
COPY packages/shared/package.json ./packages/shared/
|
|
RUN pnpm install --frozen-lockfile --filter=@tessera/web...
|
|
|
|
FROM base AS builder
|
|
WORKDIR /app
|
|
COPY --from=deps /app/ ./
|
|
COPY apps/web/ ./apps/web/
|
|
COPY packages/shared/ ./packages/shared/
|
|
COPY tsconfig.base.json ./
|
|
# quick-260916-dcz: next.config.ts liest CHANGELOG.md zur Bauzeit (Seite "Was ist neu");
|
|
# .dockerignore schliesst *.md aus und macht fuer genau diese Datei eine Ausnahme.
|
|
COPY CHANGELOG.md ./
|
|
ENV NEXT_PUBLIC_API_URL=/api-proxy
|
|
# Muss VOR dem Build stehen: Next.js bettet NEXT_PUBLIC_* zur Bauzeit ins Bundle ein.
|
|
# So spaet wie moeglich, damit die COPY-Schichten darueber im Cache bleiben.
|
|
ARG APP_VERSION
|
|
ARG APP_CHANNEL
|
|
ARG APP_COMMIT
|
|
ENV NEXT_PUBLIC_APP_VERSION=$APP_VERSION NEXT_PUBLIC_APP_CHANNEL=$APP_CHANNEL NEXT_PUBLIC_APP_COMMIT=$APP_COMMIT
|
|
RUN pnpm --filter=@tessera/web build
|
|
|
|
FROM node:24-alpine AS runner
|
|
WORKDIR /app
|
|
ENV NODE_ENV=production
|
|
ARG APP_VERSION
|
|
ARG APP_CHANNEL
|
|
ARG APP_COMMIT
|
|
ARG APP_BUILD_TIME
|
|
ENV APP_VERSION=$APP_VERSION APP_CHANNEL=$APP_CHANNEL APP_COMMIT=$APP_COMMIT APP_BUILD_TIME=$APP_BUILD_TIME
|
|
# quick-261009-p0m: Paketverwaltungen des Node-Abbilds (npm, npx, corepack, yarn) entfernen;
|
|
# der Web-Server braucht nur `node`.
|
|
# Die Ordner-/Dateinamen werden mit Platzhaltern gesucht (yarn-v1.22.22 wechselt mit dem
|
|
# Node-Abbild); die letzte Zeile laesst den Bau scheitern, falls eines der Werkzeuge
|
|
# bleibt -- sonst verpufft die Absicherung still bei einem neuen Basisabbild.
|
|
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/lib/node_modules/corepack /opt/yarn* \
|
|
/usr/local/bin/npm /usr/local/bin/npx /usr/local/bin/corepack /usr/local/bin/yarn* \
|
|
&& for c in npm npx corepack yarn yarnpkg; do \
|
|
if command -v "$c" >/dev/null 2>&1; then echo "FEHLER: $c ist noch im Abbild" >&2; exit 1; fi; \
|
|
done \
|
|
&& [ -z "$(ls -d /opt/yarn* /usr/local/lib/node_modules/npm /usr/local/lib/node_modules/corepack 2>/dev/null)" ] \
|
|
&& node --version
|
|
RUN addgroup --system --gid 1001 nodejs && \
|
|
adduser --system --uid 1001 nextjs
|
|
COPY --from=builder /app/apps/web/public ./apps/web/public
|
|
COPY --from=builder --chown=nextjs:nodejs /app/apps/web/.next/standalone ./
|
|
COPY --from=builder --chown=nextjs:nodejs /app/apps/web/.next/static ./apps/web/.next/static
|
|
USER nextjs
|
|
EXPOSE 3000
|
|
CMD ["node", "apps/web/server.js"]
|