The all-in-one image builds from the project root, and Docker only reads .dockerignore from the context root — so the ones under "API Server" and "Web App" never applied to it and every AIO build shipped the whole tree, "Phone App/build" included. A root .dockerignore allow-lists the paths that build actually copies. The dev split stack passed neither PB_BOOTSTRAP nor the SUPERADMIN vars, so it created the schema and then no user to log in with. It passes them now, and .env.example says so. WEBAPP_URL was never set anywhere, leaving the panel status page probing localhost:8090 — itself — and always reporting the Web App as down. Each compose file now points it at wherever the Web App really is, and the BFF grew a real /healthz instead of letting the SPA fallback answer probes with index.html and look healthy no matter what. In the AIO, PocketBase and the API Server drop to an unprivileged user; only nginx stays root to bind :80. The entrypoint takes ownership of the two volumes first, so data written by the old root-only image stays writable. All three images carry a HEALTHCHECK, every compose file declares one too (so depends_on still gates against an older pulled image), and web-app waits for the API Server to be serving rather than merely started. Also: pinned alpine/golang/node and PocketBase 0.39.11, so a rebuild months from now produces the same image; nginx forwards WebSocket upgrades instead of stripping them, with the map in http.d where Alpine actually reads it; and a .gitattributes keeps entrypoint.sh on LF, because a CRLF shebang from a Windows clone fails at container start with "no such file or directory". Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
58 lines
2.2 KiB
Docker
58 lines
2.2 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# --- Build stage -------------------------------------------------------------
|
|
# Compile a static Go binary. The Vue panel is pre-built into internal/api/dist
|
|
# and embedded via //go:embed, so no Node toolchain is needed here.
|
|
FROM golang:1.26-alpine3.24 AS build
|
|
|
|
WORKDIR /src
|
|
|
|
# Cache module downloads separately from the source for faster rebuilds.
|
|
COPY go.mod ./
|
|
# go.sum is optional (stdlib-only module today); copy it if present.
|
|
COPY go.su[m] ./
|
|
RUN go mod download
|
|
|
|
COPY . .
|
|
|
|
# CGO_ENABLED=0 produces a static binary that runs on a bare alpine image. The
|
|
# entry point is the cmd/server package.
|
|
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-s -w" -o /out/api-server ./cmd/server
|
|
|
|
# --- Runtime stage -----------------------------------------------------------
|
|
FROM alpine:3.24
|
|
|
|
# HTTPS calls to PocketBase need CA certificates; tzdata for correct timestamps.
|
|
RUN apk add --no-cache ca-certificates tzdata
|
|
|
|
# Run as an unprivileged user.
|
|
RUN addgroup -S app && adduser -S -G app app
|
|
|
|
COPY --from=build /out/api-server /usr/local/bin/api-server
|
|
|
|
# The server writes two files relative to its working directory: plugins.json
|
|
# (plugin enable-state + config) and .env, which the panel rewrites when a
|
|
# superadmin retargets the PocketBase connection. Both must therefore live on a
|
|
# writable, persistent path — hence /data, owned by the unprivileged user and
|
|
# declared as a volume. A named volume mounted here inherits this ownership.
|
|
RUN mkdir -p /data && chown app:app /data
|
|
WORKDIR /data
|
|
VOLUME /data
|
|
|
|
# Config comes entirely from environment variables (see .env.example).
|
|
# POCKETBASE_ADMIN_EMAIL / _PASSWORD are optional at startup: without them the
|
|
# server still runs and a superadmin can configure the connection from the panel.
|
|
ENV API_ADDR=:8080 \
|
|
PLUGINS_FILE=/data/plugins.json
|
|
EXPOSE 8080
|
|
|
|
USER app
|
|
|
|
# Liveness only: /healthz answers 200 as soon as the process is serving, and
|
|
# does not depend on PocketBase, so a database outage does not mark the
|
|
# container unhealthy. Lets compose gate dependants on condition: service_healthy.
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
|
|
CMD wget -qO- http://127.0.0.1:8080/healthz >/dev/null 2>&1 || exit 1
|
|
|
|
ENTRYPOINT ["/usr/local/bin/api-server"]
|