fix: harden native workspace root and docker gates
This commit is contained in:
@@ -19,9 +19,9 @@ RUN npm ci --omit=dev \
|
||||
FROM node:22-bookworm@sha256:7725a5c2c83eed1d36258c66efae14b1ceccd021db9ed1d9559d3335ed3d68ed AS backend-native-build
|
||||
WORKDIR /src/backend
|
||||
COPY backend/package*.json ./
|
||||
RUN npm ci
|
||||
COPY backend/native ./native
|
||||
COPY backend/scripts ./scripts
|
||||
COPY backend/native ./native
|
||||
RUN npm ci
|
||||
RUN npm run build:native
|
||||
# ---- Stage 2: backend TypeScript -> dist ----
|
||||
FROM node:22-bookworm@sha256:7725a5c2c83eed1d36258c66efae14b1ceccd021db9ed1d9559d3335ed3d68ed AS backend-build
|
||||
@@ -29,10 +29,13 @@ WORKDIR /src/backend
|
||||
COPY backend/package*.json ./
|
||||
RUN npm ci --ignore-scripts
|
||||
COPY backend/src ./src
|
||||
COPY backend/scripts ./scripts
|
||||
COPY backend/tsconfig*.json ./
|
||||
RUN npm run build
|
||||
RUN npm prune --omit=dev
|
||||
COPY --from=backend-native-build /src/backend/native/workspace-fs-at/build/Release/workspace_fs_at.node ./native/workspace-fs-at/build/Release/workspace_fs_at.node
|
||||
# fs-ext is the pinned runtime flock binding; carry its Node-22 build from the compiler stage.
|
||||
COPY --from=backend-native-build /src/backend/node_modules/fs-ext/build ./node_modules/fs-ext/build
|
||||
|
||||
# ---- Stage 2: runtime (Python 3.12 nativo + Node 22 copiato, stesso glibc bookworm) ----
|
||||
FROM python:3.12-slim-bookworm@sha256:d50fb7611f86d04a3b0471b46d7557818d88983fc3136726336b2a4c657aa30b AS runtime
|
||||
@@ -85,6 +88,7 @@ RUN ln -s /opt/venv /app/harness/.venv
|
||||
# Backend: dist + node_modules (stesso Node major 22 + glibc bookworm → compatibili)
|
||||
COPY --from=backend-build /src/backend/dist /app/backend/dist
|
||||
COPY --from=backend-build /src/backend/node_modules /app/backend/node_modules
|
||||
COPY --from=backend-build /src/backend/native/workspace-fs-at/build/Release/workspace_fs_at.node /app/backend/native/workspace-fs-at/build/Release/workspace_fs_at.node
|
||||
COPY backend/package*.json /app/backend/
|
||||
|
||||
# Runtime Pi is installed only from the committed lockfile. The image exposes its immutable
|
||||
@@ -109,6 +113,9 @@ RUN /usr/local/bin/verify-line-endings /app/docker \
|
||||
|
||||
WORKDIR /app/backend
|
||||
USER thoth
|
||||
# Compiler-free Node 22 runtime smoke: load the repo addon, fsync an anchored directory, and load fs-ext.
|
||||
RUN node --version | grep -Eq "^v22\." \
|
||||
&& node -e 'const a=require("/app/backend/native/workspace-fs-at/build/Release/workspace_fs_at.node"); const r=a.openat({parent:null,name:"/",kind:"directory",createMode:0}); a.fsyncDirectory(r.handle); a.close(r.handle); require("fs-ext")'
|
||||
EXPOSE 8787
|
||||
HEALTHCHECK --interval=15s --timeout=3s --retries=5 --start-period=30s \
|
||||
CMD curl -fsS http://127.0.0.1:8787/health || exit 1
|
||||
|
||||
Reference in New Issue
Block a user