fix(auth): address Task 13 deployment review findings
This commit is contained in:
+15
-2
@@ -7,6 +7,14 @@ ARG IMAGE_VERSION=local
|
||||
# ---- Pinned Node source for the runtime binary and npm ----
|
||||
FROM node:24.16.0-bookworm@sha256:40ad9f3064e67d6860b4bc3fe1880b2953934fd6320ada990e45fe0efa6badd7 AS node-runtime
|
||||
|
||||
# ---- Pinned native storage helper used by the authenticated backend ----
|
||||
FROM golang:1.26.5-bookworm@sha256:1ecb7edf62a0408027bd5729dfd6b1b8766e578e8df93995b225dfd0944eb651 AS tht-auth-storage-build
|
||||
WORKDIR /src/tools/tht
|
||||
COPY tools/tht/go.mod tools/tht/go.sum ./
|
||||
RUN go mod download
|
||||
COPY tools/tht ./
|
||||
RUN CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o /out/tht-auth-storage ./cmd/tht
|
||||
|
||||
# ---- Stage 0: locked Pi runtime ----
|
||||
FROM node:24.16.0-bookworm@sha256:40ad9f3064e67d6860b4bc3fe1880b2953934fd6320ada990e45fe0efa6badd7 AS pi-runtime-build
|
||||
ARG PI_VERSION
|
||||
@@ -61,7 +69,9 @@ RUN useradd --create-home --uid 10001 --shell /bin/bash thoth
|
||||
# Docker copies these owned directories into newly-created named volumes, allowing the non-root
|
||||
# runtime user to create application settings, sessions, registry snapshots, state, and locks.
|
||||
RUN mkdir -p /home/thoth/.pi/agent /data/settings /data/sessions /data/workspace-registry /data/workspace-secrets \
|
||||
&& chown -R thoth:thoth /home/thoth/.pi /data
|
||||
/data/auth/sessions /data/auth/oidc \
|
||||
&& chown -R thoth:thoth /home/thoth/.pi /data \
|
||||
&& chmod 0700 /data/auth /data/auth/sessions /data/auth/oidc
|
||||
|
||||
COPY harness/ /app/harness/
|
||||
# Pi scrive lock/settings in .pi: ownership thoth per sopravvivere al rebuild
|
||||
@@ -91,14 +101,17 @@ COPY backend/package*.json /app/backend/
|
||||
# Runtime Pi is installed only from the committed lockfile. The image exposes its immutable
|
||||
# executable directly, so no host Pi installation or writable global npm directory is needed.
|
||||
COPY --from=pi-runtime-build /opt/pi-runtime/node_modules /opt/pi-runtime/node_modules
|
||||
COPY --from=tht-auth-storage-build /out/tht-auth-storage /usr/local/bin/tht-auth-storage
|
||||
RUN ln -s /opt/pi-runtime/node_modules/.bin/pi /usr/local/bin/pi \
|
||||
&& test "$(pi --version)" = "$PI_VERSION"
|
||||
&& test "$(pi --version)" = "$PI_VERSION" \
|
||||
&& test -x /usr/local/bin/tht-auth-storage
|
||||
|
||||
ENV PATH="/opt/venv/bin:/usr/local/bin:$PATH" \
|
||||
PI_VERSION="${PI_VERSION}" \
|
||||
HOST=0.0.0.0 PORT=8787 \
|
||||
THT_HARNESS_DIR=/app/harness \
|
||||
THT_BIN=/opt/venv/bin/tht \
|
||||
THT_AUTH_STORAGE_BIN=/usr/local/bin/tht-auth-storage \
|
||||
PI_BIN=pi \
|
||||
HOME=/home/thoth
|
||||
|
||||
|
||||
Reference in New Issue
Block a user