Update Dockerfile and Compose configuration
This commit is contained in:
1 parent
35f66d879f
commit
d1003bb89b
9 files changed
+2046
-13
No files matched your search
+20
-2
@@ -47,6 +47,13 @@ RUN --mount=type=cache,id=epicnext-pnpm,target=/pnpm/store,sharing=locked \
|
||||
# Source changes invalidate compilation, but keep the installed dependencies.
|
||||
COPY . .
|
||||
|
||||
# --- Automatische GitLab Pull ---
|
||||
# Vraagt de meest recente commit op van gitlab.epicnabbo.nl (project: remco/EpicNext-Cms).
|
||||
# Bij een nieuwe commit breekt Docker hier automatisch de cache en haalt hij direct de nieuwste code binnen.
|
||||
# (remco%2FEpicNext-Cms is de URL-encoded variant van remco/EpicNext-Cms)
|
||||
ADD https://gitlab.epicnabbo.nl/api/v4/projects/remco%2FEpicNext-Cms/repository/branches/main /tmp/commit.json
|
||||
RUN git pull origin main
|
||||
|
||||
# Build the production bundle.
|
||||
# The .env file is loaded ONLY inside this RUN layer (not persisted as ENV, so no
|
||||
# secrets end up in the image) — Next.js needs NEXT_PUBLIC_* + validated build-time
|
||||
@@ -69,7 +76,18 @@ RUN --mount=type=cache,id=epicnext-next,target=/app/.next/cache,sharing=locked \
|
||||
FROM node:26.8.1-bookworm-slim AS runner
|
||||
|
||||
# Catalog Studio publishes to self-hosted Git repositories over HTTPS.
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends git ca-certificates && rm -rf /var/lib/apt/lists/*
|
||||
# curl is the fallback downloader for clone sources that block Node's TLS
|
||||
# fingerprint (e.g. Leet.city) — see import/core/curl-fetch.ts.
|
||||
# curl-impersonate ships a curl built with Chrome's exact TLS fingerprint
|
||||
# (statically-linked BoringSSL; only libz/libc required). Several sources
|
||||
# enable Cloudflare `cf-mitigated: challenge` against the distro curl's JA3,
|
||||
# so prefer the impersonated binary at runtime (curl-fetch.ts resolves it).
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends git curl ca-certificates \
|
||||
&& mkdir -p /opt/curl-impersonate \
|
||||
&& curl -fsSL "https://github.com/lwthiker/curl-impersonate/releases/download/v0.6.1/curl-impersonate-v0.6.1.x86_64-linux-gnu.tar.gz" \
|
||||
| tar -xz -C /opt/curl-impersonate \
|
||||
&& chmod +x /opt/curl-impersonate/curl_chrome116 /opt/curl-impersonate/curl-impersonate-chrome \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# The CMS writes to bind-mounted host directories (/var/www/Gamedata is owned by
|
||||
# the host's www-data user, UID/GID 33). The node base image already ships a
|
||||
@@ -107,4 +125,4 @@ VOLUME ["/app/public/nitro-assets", "/app/public/swf", "/app/storage"]
|
||||
|
||||
USER ${RUN_USER}
|
||||
|
||||
CMD ["node", "server.js"]
|
||||
CMD ["node", "server.js"]
|
||||
Reference in new issue
Block a user