nextcloud: use a named build stage for docker:cli, not ARG-in-COPY-from

the legacy (non-BuildKit) docker build this host runs doesn't expand ARGs
inside COPY --from — only FROM. Give it its own named stage instead
This commit is contained in:
2026-09-25 13:49:02 +02:00
parent cdbc850c52
commit b865978e19
+5 -4
View File
@@ -11,6 +11,10 @@ ARG BUILD_BASE
ARG RUNTIME_BASE ARG RUNTIME_BASE
ARG DOCKER_CLI ARG DOCKER_CLI
# Named so the final stage's COPY --from can reference a stage, not an ARG — the legacy builder
# this host still runs doesn't expand ARGs inside COPY --from, only inside FROM.
FROM ${DOCKER_CLI} AS dockercli
FROM ${BUILD_BASE} AS build FROM ${BUILD_BASE} AS build
# Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own # Compiled under /app/modules so `@novox/mesh-sdk` resolves upward into the base's own
# node_modules — the module is compiled against exactly the sdk it will run against. The compiler # node_modules — the module is compiled against exactly the sdk it will run against. The compiler
@@ -22,15 +26,12 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts tools/index.ts
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
FROM ${RUNTIME_BASE} FROM ${RUNTIME_BASE}
# ARGs declared before the first FROM are out of scope past it; redeclared here so COPY --from
# below can see it.
ARG DOCKER_CLI
COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist COPY --from=build /app/modules/nextcloud/dist /app/modules/nextcloud/dist
# occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs # occ runs inside nextcloud's own container, reached over the mounted docker socket — which needs
# the docker CLI itself present here, not only the socket. Copied from Docker's own official client # the docker CLI itself present here, not only the socket. Copied from Docker's own official client
# image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no # image rather than apt-installed, so this stays the one binary and nothing else (no daemon, no
# systemd unit, no package manager tree pulled in for it). # systemd unit, no package manager tree pulled in for it).
COPY --from=${DOCKER_CLI} /usr/local/bin/docker /usr/local/bin/docker COPY --from=dockercli /usr/local/bin/docker /usr/local/bin/docker
# Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a # Every serve-time entrypoint, loaded by the runtime in serve mode: tools and events serve, and a
# provider's provisioner runs its reconcile loop in the same process, with the broker connected — # provider's provisioner runs its reconcile loop in the same process, with the broker connected —
# the convention novox/hq issues 060/061 settled. A container that instead ran only its # the convention novox/hq issues 060/061 settled. A container that instead ran only its