* chore: update Dockerfile to run it as non-root user across multiple apps and install shadow-utils * chore: update Dockerfiles to install shadow-utils using dnf and ensure non-root user execution in admin, web, and live apps * chore: add Dockerfile configurations for Node Runner and Flux, including shadow-utils installation and non-root user execution * chore: update Dockerfile.fips to set permissions for /app and /var/tls, and expose port 8000 * chore: update Dockerfiles to install crypto-policies and set FIPS mode across multiple applications * chore: replace microdnf with dnf for installing crypto-policies in Dockerfiles for admin and web applications * chore: update Dockerfiles to set up Nginx directories and rebuild sharp for UBI compatibility in admin, live, and web applications * chore: update Dockerfiles to include /run directory for Nginx and adjust ownership settings in admin, live, and web applications * chore: refactor Dockerfile.fips to use node:22-alpine, streamline dependency installation, and adjust working directory structure for the live application * chore: update Dockerfile.fips to use UBI base image, streamline dependency installation, and enhance runtime configuration for the live application * fix: exclude src/scripts from tsc to resolve missing @hocuspocus/provider types * feat: add FIPS Docker image variables for Node Runner and Flux * fix: update TURBO_VERSION to 2.8.13 and clean up Dockerfile --------- Co-authored-by: Palanikannan M <[email protected]>
86 lines
2.9 KiB
Docker
86 lines
2.9 KiB
Docker
# syntax=docker/dockerfile:1.7
|
|
FROM node:22-alpine AS base
|
|
|
|
# Setup pnpm package manager with corepack and configure global bin directory for caching
|
|
ENV PNPM_HOME="/pnpm"
|
|
ENV PATH="$PNPM_HOME:$PATH"
|
|
RUN corepack enable
|
|
|
|
# *****************************************************************************
|
|
# STAGE 1: Prune the project
|
|
# *****************************************************************************
|
|
FROM base AS builder
|
|
# Check https://github.com/nodejs/docker-node/tree/b4117f9333da4138b03a546ec926ef50a31506c3#nodealpine to understand why libc6-compat might be needed.
|
|
RUN apk update
|
|
RUN apk add --no-cache libc6-compat
|
|
# Set working directory
|
|
WORKDIR /app
|
|
ARG TURBO_VERSION=2.5.6
|
|
RUN corepack enable pnpm && pnpm add -g turbo@${TURBO_VERSION}
|
|
COPY . .
|
|
RUN turbo prune --scope=plane-runner-host --docker
|
|
|
|
# *****************************************************************************
|
|
# STAGE 2: Install dependencies & build the project
|
|
# *****************************************************************************
|
|
# Add lockfile and package.json's of isolated subworkspace
|
|
FROM base AS installer
|
|
RUN apk update
|
|
RUN apk add --no-cache libc6-compat
|
|
WORKDIR /app
|
|
|
|
# First install dependencies (as they change less often)
|
|
COPY .gitignore .gitignore
|
|
COPY --from=builder /app/out/json/ .
|
|
COPY --from=builder /app/out/pnpm-lock.yaml ./pnpm-lock.yaml
|
|
RUN corepack enable pnpm
|
|
RUN --mount=type=cache,id=pnpm-store,target=/pnpm/store pnpm fetch --store-dir=/pnpm/store
|
|
|
|
# Build the project and its dependencies
|
|
COPY --from=builder /app/out/full/ .
|
|
COPY turbo.json turbo.json
|
|
ENV CI=true
|
|
RUN --mount=type=cache,id=pnpm-store,target=/pnpm/store pnpm install --store-dir=/pnpm/store
|
|
|
|
ENV TURBO_TELEMETRY_DISABLED=1
|
|
|
|
RUN pnpm turbo run build --filter=plane-runner-host
|
|
|
|
# *****************************************************************************
|
|
# STAGE 3: Run the project
|
|
# *****************************************************************************
|
|
FROM registry.access.redhat.com/ubi10/nodejs-22 AS runner
|
|
|
|
USER root
|
|
|
|
RUN dnf install -y shadow-utils crypto-policies crypto-policies-scripts && dnf clean all
|
|
|
|
RUN update-crypto-policies --set FIPS
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=installer /app/apps/runners/node-runner/dist ./apps/runners/node-runner/dist
|
|
COPY --from=installer /app/apps/runners/node-runner/node_modules ./apps/runners/node-runner/node_modules
|
|
COPY --from=installer /app/apps/runners/node-runner/package.json ./apps/runners/node-runner/package.json
|
|
COPY --from=installer /app/node_modules ./node_modules
|
|
|
|
# Directory where script packages will be installed at runtime
|
|
RUN mkdir -p /app/scripts
|
|
|
|
COPY LICENSE.txt .
|
|
RUN mkdir -p /usr/share/licenses/plane/
|
|
COPY LICENSE.txt /usr/share/licenses/plane/LICENSE.txt
|
|
|
|
RUN groupadd -g 1000 node && useradd -u 1000 -g node -s /bin/sh -d /app node
|
|
|
|
RUN chown -R node:node /app
|
|
|
|
USER node
|
|
|
|
ENV NODE_ENV=production
|
|
ENV TURBO_TELEMETRY_DISABLED=1
|
|
ENV NPM_CONFIG_CACHE=/tmp/.npm-cache
|
|
|
|
EXPOSE 3000
|
|
|
|
CMD ["node", "apps/runners/node-runner/dist/index.js"] |