# syntax=docker/dockerfile:1 # ---------- deps: install once, cached until package.json changes ---------- FROM node:22.12-alpine3.20 AS deps WORKDIR /app # package-lock.json* is optional: this repo gitignores it. Commit it to get # reproducible installs (npm install honours a lockfile when present). COPY package.json package-lock.json* ./ RUN npm install --no-audit --no-fund # ---------- build: tsc -b && vite build ---------- FROM node:22.12-alpine3.20 AS build WORKDIR /app # Vite inlines import.meta.env.VITE_* at build time, so these are build args, # NOT runtime env. Changing them requires a rebuild. ARG VITE_API_BASE_URL ARG VITE_RECAPTCHA_SITE_KEY ENV VITE_API_BASE_URL=${VITE_API_BASE_URL} \ VITE_RECAPTCHA_SITE_KEY=${VITE_RECAPTCHA_SITE_KEY} \ NODE_ENV=production COPY --from=deps /app/node_modules ./node_modules COPY . . RUN test -n "$VITE_API_BASE_URL" || (echo "VITE_API_BASE_URL build arg is required" >&2; exit 1) \ && npm run build # ---------- runtime: static files only, no node, non-root ---------- FROM nginxinc/nginx-unprivileged:1.29-alpine AS runtime # Config baked into the image; no bind mounts. COPY nginx.conf /etc/nginx/conf.d/default.conf COPY --from=build --chown=nginx:nginx /app/dist /usr/share/nginx/html # Image already runs as uid 101 (nginx); stated explicitly. USER nginx EXPOSE 8080 HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ CMD wget -qO- http://127.0.0.1:8080/healthz || exit 1