Docker: a build context that isn't 3.6GB, and health you can see
The all-in-one image builds from the project root, and Docker only reads .dockerignore from the context root — so the ones under "API Server" and "Web App" never applied to it and every AIO build shipped the whole tree, "Phone App/build" included. A root .dockerignore allow-lists the paths that build actually copies. The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so it created the schema and then no user to log in with. It passes them now, and .env.example says so. WEBAPP_URL was never set anywhere, leaving the panel status page probing localhost:8090 — itself — and always reporting the Web App as down. Each compose file now points it at wherever the Web App really is, and the BFF grew a real /healthz instead of letting the SPA fallback answer probes with index.html and look healthy no matter what. In the AIO, PocketBase and the API Server drop to an unprivileged user; only nginx stays root to bind :80. The entrypoint takes ownership of the two volumes first, so data written by the old root-only image stays writable. All three images carry a HEALTHCHECK, every compose file declares one too (so depends_on still gates against an older pulled image), and web-app waits for the API Server to be serving rather than merely started. Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months from now produces the same image; nginx forwards WebSocket upgrades instead of stripping them, with the map in http.d where Alpine actually reads it; and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from a Windows clone fails at container start with "no such file or directory". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
9487de84b0
commit
f08849e50c
@@ -0,0 +1,26 @@
|
||||
# Build context for Docker-AIO/Dockerfile, which builds from the PROJECT ROOT so
|
||||
# it can reach both "API Server/" and "Web App/". Docker reads .dockerignore only
|
||||
# from the context root, so the per-directory ignore files under "API Server/"
|
||||
# and "Web App/" do NOT apply to that build — this file is what keeps it small.
|
||||
# Without it the daemon receives ~3.6 GB (Phone App/build alone is 3 GB).
|
||||
#
|
||||
# It is an allow-list: everything is excluded, then the exact paths the AIO
|
||||
# Dockerfile copies are added back. If you add a COPY to that Dockerfile, add
|
||||
# its path here too or the build fails with "no source files were specified".
|
||||
*
|
||||
|
||||
# --- Stage 1: the Go API Server ---------------------------------------------
|
||||
!API Server/go.mod
|
||||
!API Server/go.sum
|
||||
!API Server/cmd
|
||||
!API Server/internal
|
||||
|
||||
# --- Stage 2: the Vue Web App ------------------------------------------------
|
||||
!Web App/web
|
||||
|
||||
# ...but never its dependencies; npm ci reinstalls them inside the image.
|
||||
Web App/web/node_modules
|
||||
|
||||
# Secrets and local artifacts, re-excluded in case a rule above lets them in.
|
||||
**/.env
|
||||
**/*.log
|
||||
Reference in New Issue
Block a user