The tool runtime's recipe starts FROM the base its manifest declares (ADR 0097) #12

Merged
jschoubben merged 1 commits from multiple-fixes into main 2026-09-21 20:58:23 +00:00
2 changed files with 10 additions and 3 deletions
Showing only changes of commit 2990b2d5a4 - Show all commits
+4 -3
View File
@@ -1,3 +1,4 @@
ARG NODE_BASE=node:22-bookworm-slim
# Three stages, two published images: the one modules are COMPILED in, and the one they RUN in.
#
# **They were the same image, and that was a mistake.** A module's recipe starts from this and
@@ -13,7 +14,7 @@
# docker may carry no buildx.
# ---- deps: node_modules resolved from the mesh's registry, credential and all ----------------
FROM node:22-bookworm-slim AS deps
FROM ${NODE_BASE} AS deps
RUN apt-get update \
&& apt-get install -y --no-install-recommends git ca-certificates \
&& rm -rf /var/lib/apt/lists/*
@@ -26,7 +27,7 @@ COPY .npmrc ./.npmrc
RUN npm install --no-audit --no-fund
# ---- toolchain: what a module is compiled in, WITHOUT the credential --------------------------
FROM node:22-bookworm-slim AS toolchain
FROM ${NODE_BASE} AS toolchain
WORKDIR /app
COPY package.json ./
# The resolved libraries, but not the .npmrc that resolved them.
@@ -45,7 +46,7 @@ FROM toolchain AS lean
RUN npm prune --omit=dev
# ---- runtime: what a module runs in -----------------------------------------------------------
FROM node:22-bookworm-slim AS runtime
FROM ${NODE_BASE} AS runtime
WORKDIR /app
COPY package.json ./
COPY --from=lean /app/node_modules ./node_modules
+6
View File
@@ -16,6 +16,12 @@
"from": "Dockerfile",
"target": "runtime"
}
],
"on": [
{
"arg": "NODE_BASE",
"image": "node@sha256:48e4b67d85f87bd551df43704e24d252f56cc5f8e9718841aace50f19948f0f9"
}
]
},
"resources": []