From 2990b2d5a4f49c5dc78c68e39cb1e1fc0c376546 Mon Sep 17 00:00:00 2001 From: jochen Date: Mon, 21 Sep 2026 22:16:10 +0200 Subject: [PATCH] The tool runtime's recipe starts FROM the base its manifest declares (novox/hq ADR 0097) --- Dockerfile | 7 ++++--- module.json | 6 ++++++ 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/Dockerfile b/Dockerfile index 143613b..1fe0db8 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,3 +1,4 @@ +ARG NODE_BASE=node:22-bookworm-slim # Three stages, two published images: the one modules are COMPILED in, and the one they RUN in. # # **They were the same image, and that was a mistake.** A module's recipe starts from this and @@ -13,7 +14,7 @@ # docker may carry no buildx. # ---- deps: node_modules resolved from the mesh's registry, credential and all ---------------- -FROM node:22-bookworm-slim AS deps +FROM ${NODE_BASE} AS deps RUN apt-get update \ && apt-get install -y --no-install-recommends git ca-certificates \ && rm -rf /var/lib/apt/lists/* @@ -26,7 +27,7 @@ COPY .npmrc ./.npmrc RUN npm install --no-audit --no-fund # ---- toolchain: what a module is compiled in, WITHOUT the credential -------------------------- -FROM node:22-bookworm-slim AS toolchain +FROM ${NODE_BASE} AS toolchain WORKDIR /app COPY package.json ./ # The resolved libraries, but not the .npmrc that resolved them. @@ -45,7 +46,7 @@ FROM toolchain AS lean RUN npm prune --omit=dev # ---- runtime: what a module runs in ----------------------------------------------------------- -FROM node:22-bookworm-slim AS runtime +FROM ${NODE_BASE} AS runtime WORKDIR /app COPY package.json ./ COPY --from=lean /app/node_modules ./node_modules diff --git a/module.json b/module.json index bb96901..10072e8 100644 --- a/module.json +++ b/module.json @@ -16,6 +16,12 @@ "from": "Dockerfile", "target": "runtime" } + ], + "on": [ + { + "arg": "NODE_BASE", + "image": "node@sha256:48e4b67d85f87bd551df43704e24d252f56cc5f8e9718841aace50f19948f0f9" + } ] }, "resources": []