Become a nox mesh module
The mesh builds all three images from this repository and a commit (novox/hq ADR 0069) — the Drone pipeline that built outside Docker and copied its output in retires with the predecessor. One module carries the API and every client instance: eef and filip are the same built client under two names, which is a second route contribution, not a second module (ADR 0015 — an application is one repository). The clients drop nginx and its bash startup script: the node the API already needs serves the static build too (client-server/serve.mjs — files, the SPA fallback, env-config.js from the environment), so the whole module stands on one declared base. What the machine serves does not move: the same four public names, the same four machine ports. MongoDB, the bucket and every credential arrive as mesh grants instead of hand-set environment; SUPER_ADMIN_KEY stops being a default written in code and becomes a minted secret.
This commit is contained in:
+25
-24
@@ -1,26 +1,27 @@
|
||||
FROM nginx:1.15.2-alpine
|
||||
# The photos client, built by the mesh from this repository (novox/hq ADR 0069): the react build
|
||||
# happens here rather than in a CI step that copied its output in.
|
||||
#
|
||||
# One base, named rather than pinned (novox/hq issue 044), declared in module.json's `build.on`:
|
||||
# the site is compiled and served by the same node the API already needs. Serving is
|
||||
# client-server/serve.mjs — static files, the SPA fallback, and env-config.js regenerated from the
|
||||
# container's environment at start, which is how one built image serves under any API URL. The
|
||||
# nginx-and-bash arrangement this replaces did the same with two more moving parts.
|
||||
#
|
||||
# The build context is the repository root; every COPY says so.
|
||||
ARG NODE_BASE
|
||||
|
||||
# Nginx config
|
||||
RUN rm -rf /etc/nginx/conf.d
|
||||
COPY ./conf /etc/nginx
|
||||
FROM ${NODE_BASE} AS build
|
||||
WORKDIR /build
|
||||
COPY client/package.json client/package-lock.json ./
|
||||
RUN npm ci
|
||||
COPY client/public ./public
|
||||
COPY client/src ./src
|
||||
COPY client/.env ./.env
|
||||
RUN npm run build
|
||||
|
||||
# Static build
|
||||
COPY ./build /usr/share/nginx/html/
|
||||
|
||||
# Default port exposure
|
||||
EXPOSE 80
|
||||
|
||||
# Copy .env file and shell script to container
|
||||
WORKDIR /usr/share/nginx/html
|
||||
|
||||
COPY scripts/env.sh .
|
||||
COPY .env .
|
||||
|
||||
# Add bash
|
||||
RUN apk add --no-cache bash
|
||||
|
||||
# Make our shell script executable
|
||||
RUN chmod +x env.sh
|
||||
|
||||
# Start Nginx server
|
||||
CMD ["/bin/bash", "-c", "/usr/share/nginx/html/env.sh && nginx -g \"daemon off;\""]
|
||||
FROM ${NODE_BASE}
|
||||
ENV NODE_ENV=production
|
||||
COPY client-server/serve.mjs /serve.mjs
|
||||
COPY --from=build /build/build /site/
|
||||
COPY client/.env /site/.env
|
||||
CMD ["node", "/serve.mjs"]
|
||||
|
||||
Reference in New Issue
Block a user