Docker: a build context that isn't 3.6GB, and health you can see
The all-in-one image builds from the project root, and Docker only reads .dockerignore from the context root — so the ones under "API Server" and "Web App" never applied to it and every AIO build shipped the whole tree, "Phone App/build" included. A root .dockerignore allow-lists the paths that build actually copies. The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so it created the schema and then no user to log in with. It passes them now, and .env.example says so. WEBAPP_URL was never set anywhere, leaving the panel status page probing localhost:8090 — itself — and always reporting the Web App as down. Each compose file now points it at wherever the Web App really is, and the BFF grew a real /healthz instead of letting the SPA fallback answer probes with index.html and look healthy no matter what. In the AIO, PocketBase and the API Server drop to an unprivileged user; only nginx stays root to bind :80. The entrypoint takes ownership of the two volumes first, so data written by the old root-only image stays writable. All three images carry a HEALTHCHECK, every compose file declares one too (so depends_on still gates against an older pulled image), and web-app waits for the API Server to be serving rather than merely started. Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months from now produces the same image; nginx forwards WebSocket upgrades instead of stripping them, with the map in http.d where Alpine actually reads it; and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from a Windows clone fails at container start with "no such file or directory". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
9487de84b0
commit
f08849e50c
@@ -6,11 +6,17 @@ tmp/
|
||||
|
||||
# Panel source & tooling — the built output in internal/api/dist is committed
|
||||
# and embedded at compile time, so the source tree is not needed in the image.
|
||||
panel/node_modules/
|
||||
panel/dist/
|
||||
# Excluding all of panel/ (not just its node_modules) also keeps edits to the
|
||||
# panel source from invalidating the `COPY . .` layer on every rebuild.
|
||||
panel/
|
||||
|
||||
# Runtime state written by a local (non-container) run. In the image this file
|
||||
# lives on the /data volume, so a copy from the host would only bust the cache.
|
||||
plugins.json
|
||||
|
||||
# VCS / editor noise
|
||||
.git/
|
||||
.gitignore
|
||||
.claude/
|
||||
.vscode/
|
||||
.idea/
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
# --- Build stage -------------------------------------------------------------
|
||||
# Compile a static Go binary. The Vue panel is pre-built into internal/api/dist
|
||||
# and embedded via //go:embed, so no Node toolchain is needed here.
|
||||
FROM golang:1.26-alpine AS build
|
||||
FROM golang:1.26-alpine3.24 AS build
|
||||
|
||||
WORKDIR /src
|
||||
|
||||
@@ -20,7 +20,7 @@ COPY . .
|
||||
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-s -w" -o /out/api-server ./cmd/server
|
||||
|
||||
# --- Runtime stage -----------------------------------------------------------
|
||||
FROM alpine:latest
|
||||
FROM alpine:3.24
|
||||
|
||||
# HTTPS calls to PocketBase need CA certificates; tzdata for correct timestamps.
|
||||
RUN apk add --no-cache ca-certificates tzdata
|
||||
@@ -47,4 +47,11 @@ ENV API_ADDR=:8080 \
|
||||
EXPOSE 8080
|
||||
|
||||
USER app
|
||||
|
||||
# Liveness only: /healthz answers 200 as soon as the process is serving, and
|
||||
# does not depend on PocketBase, so a database outage does not mark the
|
||||
# container unhealthy. Lets compose gate dependants on condition: service_healthy.
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
|
||||
CMD wget -qO- http://127.0.0.1:8080/healthz >/dev/null 2>&1 || exit 1
|
||||
|
||||
ENTRYPOINT ["/usr/local/bin/api-server"]
|
||||
|
||||
@@ -17,6 +17,10 @@ services:
|
||||
# superadmin can configure it from the panel; management endpoints 503 until then.
|
||||
POCKETBASE_ADMIN_EMAIL: "${PB_ADMIN_EMAIL}"
|
||||
POCKETBASE_ADMIN_PASSWORD: "${PB_ADMIN_PASSWORD}"
|
||||
# Probed by the panel status page. Point it at wherever the Web App runs
|
||||
# as seen from THIS container — the default (localhost:8090) is this
|
||||
# container itself, so it must be set for the status page to be accurate.
|
||||
WEBAPP_URL: "${WEBAPP_URL:-http://host.docker.internal:8090}"
|
||||
# Browser origins allowed by CORS (native apps are exempt). Point this at
|
||||
# the Web App origin; add http://localhost:5173 when running Vite in dev.
|
||||
CORS_ALLOW_ORIGINS: "${CORS_ALLOW_ORIGINS:-http://localhost:8090}"
|
||||
@@ -27,9 +31,20 @@ services:
|
||||
# base derived from request headers (set it when behind a reverse proxy).
|
||||
OCPP_REQUIRE_TLS: "${OCPP_REQUIRE_TLS:-true}"
|
||||
OCPP_PUBLIC_URL: "${OCPP_PUBLIC_URL:-}"
|
||||
extra_hosts:
|
||||
# Makes host.docker.internal resolve on Linux too (Docker Desktop provides
|
||||
# it already), so the WEBAPP_URL default above can reach a Web App running
|
||||
# on the host rather than in this compose file.
|
||||
- "host.docker.internal:host-gateway"
|
||||
volumes:
|
||||
# Holds plugins.json and the .env the panel writes back — see Dockerfile.
|
||||
- api_data:/data
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8080/healthz || exit 1"]
|
||||
interval: 10s
|
||||
timeout: 3s
|
||||
retries: 12
|
||||
start_period: 20s
|
||||
|
||||
volumes:
|
||||
api_data:
|
||||
|
||||
Reference in New Issue
Block a user