build: harden image build inputs

This commit is contained in:
2026-08-04 16:33:39 +02:00
parent d42fdf4b71
commit e2264ee295
7 changed files with 52 additions and 28 deletions
+3 -2
View File
@@ -1,7 +1,7 @@
# syntax=docker/dockerfile:1.7
# thothii-frontend: build Vite (React) + nginx-unprivileged (porta 8080).
ARG IMAGE_VERSION=local
FROM node:22-bookworm AS build
FROM node:22-bookworm@sha256:7725a5c2c83eed1d36258c66efae14b1ceccd021db9ed1d9559d3335ed3d68ed AS build
WORKDIR /src
COPY frontend/package*.json ./
RUN npm ci
@@ -9,7 +9,7 @@ COPY frontend/ ./
ENV VITE_BASE=/ VITE_BACKEND_URL=/api
RUN npm run build
FROM nginxinc/nginx-unprivileged:1.27-alpine AS runtime
FROM nginxinc/nginx-unprivileged:1.27-alpine@sha256:65e3e85dbaed8ba248841d9d58a899b6197106c23cb0ff1a132b7bfe0547e4c0 AS runtime
ARG IMAGE_VERSION
LABEL org.opencontainers.image.title="thothii-frontend" \
org.opencontainers.image.version="${IMAGE_VERSION}" \
@@ -18,6 +18,7 @@ COPY --from=build /src/dist /usr/share/nginx/html
COPY docker/nginx.conf.template /etc/nginx/templates/default.conf.template
COPY --chmod=755 docker/frontend-entrypoint.sh /usr/local/bin/frontend-entrypoint
COPY --chmod=755 docker/validate-frontend-api-upstream.sh /usr/local/bin/validate-frontend-api-upstream
COPY --chmod=755 docker/smoke/frontend-smoke.sh /usr/local/bin/frontend-config-smoke
ENTRYPOINT ["/usr/local/bin/frontend-entrypoint"]
CMD ["nginx", "-g", "daemon off;"]
EXPOSE 8080