-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.dev.server
More file actions
51 lines (44 loc) · 2.52 KB
/
Copy pathDockerfile.dev.server
File metadata and controls
51 lines (44 loc) · 2.52 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
# syntax=docker/dockerfile:1.7
#
# Development image for the Hono/Bun server. Bun runs the TS entrypoint;
# pnpm (via corepack) owns dependency resolution so the lockfile stays the
# single source of truth (`bun install` would trip the `only-allow pnpm`
# preinstall guard anyway).
#
# Base is the node image (so corepack/pnpm work natively); the bun binary is
# copied in from the official bun image. Both pinned by manifest digest per
# .claude/rules/supply-chain.md §4.
# oven/bun:1.4.0-debian
FROM oven/bun@sha256:5bb0f9be3a1a36a03e27c9a9dd894a3b1ad26657155c7df4dda771e17bf872ef AS bun-src
# node:24.19.0-bookworm (matches .nvmrc). NOT the -bookworm-slim variant: the
# slim image omits git, and `apt-get install git` at build time is currently
# broken on bookworm-slim because apt 2.6.1's apt-key signature-split pipeline
# mis-parses the multi-signature InRelease Debian ships (gpgv validates the
# file directly; apt's wrapper exits 1 with an empty parse). The non-slim
# image ships git preinstalled, so we never invoke apt at build time.
# Production (Dockerfile) stays on -slim because it doesn't need git.
FROM node@sha256:4196d66a565c6f195728d9952f161f4adfe2ad753052a08b7ec7f1c5a6bda42b
COPY --from=bun-src /usr/local/bin/bun /usr/local/bin/bun
# `git` ships in the base image — required because package.json's `prepare`
# script runs `lefthook install` after every `pnpm install`, and lefthook
# shells out to git.
# Spelled out rather than the bare `corepack prepare --activate` the CI jobs
# use: this runs before package.json is COPYed in, so corepack has no
# `packageManager` field to read. Keep it equal to package.json's
# `packageManager` — a mismatch means `pnpm dev` resolves the lockfile with a
# different pnpm than CI and every developer.
RUN corepack enable && corepack prepare pnpm@11.23.0 --activate
# Pre-create /app/node_modules and /data owned by the dev UID so the named
# volumes attached at runtime inherit that ownership (Docker copies the
# image directory into a fresh named volume on first mount). Without this,
# the volumes default to root-owned: pnpm install fails with EACCES on
# /app/node_modules; the SQLite store fails with EACCES on /data when
# openStoreFromEnv calls mkdirSync(XRAY_DATA_DIR).
#
# UID/GID come from build args — `pnpm dev` exports the host UID/GID into
# compose, which forwards them here. Defaults to 1000:1000 for the common
# case but rebuilds per-developer if their host IDs differ.
ARG UID=1000
ARG GID=1000
RUN mkdir -p /app/node_modules /data && chown -R ${UID}:${GID} /app /data
WORKDIR /app