fix(docker): harden image and automate safe VPS updates

- Use floating node:alpine that tracks the latest supported LTS; pnpm
  bootstrap follows package.json's packageManager pin.
- Drop corepack (removed from node:26), install pnpm via npm global.
- Add pnpm fetch + offline install for stable dependency-layer caching.
- Run as non-root nextjs (UID/GID 33 = host www-data) with tini as PID 1
  for correct signal handling.
- Open node engines to >=20.9.0 so patches/minors float automatically.
- Add docker-preflight.sh (per-VPS checks incl. --fix) and gate docker-update.sh
  so Node major upgrades require explicit review while patches deploy silently.
This commit is contained in:
openhands committed 2026-09-07 11:22:30 +02:00
1 parent 7033d65846
commit 539e6d3fad
5 files changed
+201 -86

No files matched your search

+3 -6
View File
@@ -7,11 +7,6 @@ services:
# build containers on the bridge network have no outbound NAT/DNS. Build on
# the host network instead so pnpm/npm/yarn can reach the registry.
network: host
args:
# Run as the host owner (www-data = UID/GID 33, already present in the
# node base image) of /var/www/Gamedata so the container can read + write
# the shared gamedata directory.
RUN_USER: "www-data"
container_name: epicnext-cms
# Runs on the host network so existing 127.0.0.1 refs in .env keep working:
# MariaDB (3306), DragonflyDB/Redis (6379), emulator RCON (3003) + API (3001),
@@ -22,6 +17,8 @@ services:
restart: unless-stopped
env_file:
- .env
environment:
- HOSTNAME=0.0.0.0
volumes:
# ── Write targets (runtime imports/uploads, persistent on the host) ──
# The CMS writes imported furni/figures/pets/effects here (see
@@ -81,4 +78,4 @@ services:
# - "3030:3030"
# restart: unless-stopped
# volumes:
# - /var/www/Gamedata:/var/www/Gamedata
# - /var/www/Gamedata:/var/www/Gamedata