The tool runtime's recipe starts FROM the base its manifest declares (novox/hq ADR 0097)

This commit is contained in:
2026-09-21 22:16:10 +02:00
parent bca504b521
commit 2990b2d5a4
2 changed files with 10 additions and 3 deletions
+4 -3
View File
@@ -1,3 +1,4 @@
ARG NODE_BASE=node:22-bookworm-slim
# Three stages, two published images: the one modules are COMPILED in, and the one they RUN in.
#
# **They were the same image, and that was a mistake.** A module's recipe starts from this and
@@ -13,7 +14,7 @@
# docker may carry no buildx.
# ---- deps: node_modules resolved from the mesh's registry, credential and all ----------------
FROM node:22-bookworm-slim AS deps
FROM ${NODE_BASE} AS deps
RUN apt-get update \
&& apt-get install -y --no-install-recommends git ca-certificates \
&& rm -rf /var/lib/apt/lists/*
@@ -26,7 +27,7 @@ COPY .npmrc ./.npmrc
RUN npm install --no-audit --no-fund
# ---- toolchain: what a module is compiled in, WITHOUT the credential --------------------------
FROM node:22-bookworm-slim AS toolchain
FROM ${NODE_BASE} AS toolchain
WORKDIR /app
COPY package.json ./
# The resolved libraries, but not the .npmrc that resolved them.
@@ -45,7 +46,7 @@ FROM toolchain AS lean
RUN npm prune --omit=dev
# ---- runtime: what a module runs in -----------------------------------------------------------
FROM node:22-bookworm-slim AS runtime
FROM ${NODE_BASE} AS runtime
WORKDIR /app
COPY package.json ./
COPY --from=lean /app/node_modules ./node_modules