| Marc Kupietz | 03ba301 | 2025-12-11 16:14:05 +0100 | [diff] [blame] | 1 | # Multi-stage Docker build for size optimization |
| 2 | FROM node:alpine AS builder |
| 3 | |
| 4 | # Set the working directory |
| 5 | WORKDIR /app |
| 6 | |
| 7 | # Copy package files first (for better layer caching) |
| 8 | COPY package*.json ./ |
| 9 | |
| 10 | # Install dependencies (production only) |
| 11 | RUN npm ci --only=production |
| 12 | |
| 13 | # Production stage |
| 14 | FROM node:alpine AS production |
| 15 | |
| 16 | # metadata |
| 17 | LABEL maintainer="Marc Kupietz <kupietz@ids-mannheim.de>" |
| 18 | |
| 19 | # Install minimal runtime dependencies |
| 20 | RUN apk add --no-cache --update \ |
| 21 | shadow \ |
| 22 | && rm -rf /var/cache/apk/* |
| 23 | |
| 24 | # Add non-root user |
| 25 | RUN groupadd -r appuser && useradd -r -g appuser appuser |
| 26 | |
| 27 | # Set the working directory |
| 28 | WORKDIR /app |
| 29 | |
| 30 | # Copy node_modules from builder |
| 31 | COPY --from=builder --chown=appuser:appuser /app/node_modules /app/node_modules |
| 32 | |
| 33 | # Copy application source |
| 34 | COPY --chown=appuser:appuser package.json /app/ |
| 35 | COPY --chown=appuser:appuser src /app/src |
| 36 | |
| 37 | # Copy entry point |
| 38 | COPY --chown=appuser:appuser docker-entrypoint.sh /docker-entrypoint.sh |
| 39 | RUN chmod +x /docker-entrypoint.sh |
| 40 | |
| 41 | # Switch to non-root user |
| 42 | USER appuser |
| 43 | |
| 44 | # Define the entry point |
| 45 | ENTRYPOINT ["/docker-entrypoint.sh"] |