# n8n with what its workflows reach for beyond the upstream image. # # The base is named, not pinned here (novox/hq issue 044): module.json's `build.on` declares N8N_BASE # as the upstream image by digest, and the mesh hands the build its own copy (ADR 0097). ARG N8N_BASE FROM ${N8N_BASE} USER root # - `media` (GID 2000), with `node` in it: the shared media library is group-writable by the # operator's media group, and a workflow files downloads into it. A container resource cannot add # a supplementary group, so the image's own /etc/group carries it. 2000 is the operator's media # group today; novox/hq 153 proposes reading it from the accessed data (${access::gid}). # - uuid, pinned to the version the workflows were written against: Code nodes require() it # (NODE_FUNCTION_ALLOW_EXTERNAL=*), and a Code node can only require what is installed. RUN apk add --no-cache shadow \ && groupadd -g 2000 media \ && usermod -aG media node \ && npm install -g uuid@14.0.1 USER node