build: one image, nginx in front of the backend on loopback (closes #52)
check / check (push) Successful in 12s
check / check (push) Successful in 12s
The root Dockerfile builds the only image; Dockerfile.backend is gone. Its stages: lint, a Go stage that runs the tests and builds netwatch-server, the node stage, and an nginx runtime. nginx serves dist/ on 8080 and proxies /api/ and /.well-known/healthcheck to the backend on 127.0.0.1:8081. bin/entrypoint.sh starts both, turns TERM or INT into a stop of both, and exits non-zero when either exits on its own. The backend runs as user netwatch and keeps reports on the /data volume. New setting BIND_ADDRESS (empty: every interface). STOPSIGNAL is SIGTERM, since the nginx image's SIGQUIT would miss the entrypoint. script/docker is the org model verbatim. Model: opus-5-5
This commit was merged in pull request #62.
This commit is contained in:
+2
-2
@@ -27,8 +27,8 @@ NVM_VERSION="0.40.3"
|
||||
# sha256 of https://github.com/nvm-sh/nvm/archive/refs/tags/v0.40.3.tar.gz
|
||||
NVM_SHA256="5f4d6aaa04a177dc93c985e31dbc411ab6b8c6e1e21d8015dbc1372625fcd1d0"
|
||||
YARN_VERSION="1.22.22"
|
||||
# The Go inside the golang:1.25-alpine image Dockerfile.backend builds
|
||||
# with, 2026-08-09. The archive hashes are in ensure_go.
|
||||
# The Go inside the golang:1.25-alpine image Dockerfile builds the
|
||||
# backend with, 2026-08-09. The archive hashes are in ensure_go.
|
||||
GO_VERSION="1.25.7"
|
||||
|
||||
BIN_DIR="$HOME/.local/bin"
|
||||
|
||||
+4
-6
@@ -1,9 +1,8 @@
|
||||
#!/bin/sh
|
||||
# script/cibuild: run the CI build. It builds both images: the frontend
|
||||
# from Dockerfile and the backend from Dockerfile.backend. Each runs its
|
||||
# half of the checks as build steps, so a successful cibuild implies the
|
||||
# whole repo is green. This is the only build step the Gitea workflow
|
||||
# runs.
|
||||
# script/cibuild: run the CI build: build the one image from Dockerfile,
|
||||
# whose stages run the checks as build steps (the backend's fmt-check,
|
||||
# lint and tests, and the frontend's test, lint and fmt-check). This is
|
||||
# the only build step the Gitea workflow runs.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
@@ -11,7 +10,6 @@ ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
timeout 300 docker build .
|
||||
timeout 300 docker build -f Dockerfile.backend .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
+14
-6
@@ -1,7 +1,8 @@
|
||||
#!/bin/sh
|
||||
# script/docker: build both Docker images, tagged with the project name
|
||||
# from script/projectname: the frontend as <name>, from Dockerfile, and
|
||||
# the backend as <name>-server, from Dockerfile.backend.
|
||||
# script/docker: build the Docker image tagged with the project name.
|
||||
# Identical in all repos; the tag comes from script/projectname.
|
||||
# --no-cache because the gate phases the final stage depends on are RUN
|
||||
# steps, and a cached one is a check that did not run.
|
||||
set -eu
|
||||
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
@@ -9,9 +10,16 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
name="$("$SCRIPT_DIR/projectname")"
|
||||
timeout 300 docker build -t "$name" .
|
||||
timeout 300 docker build -t "$name-server" -f Dockerfile.backend .
|
||||
# Own line: a failing command substitution inside an argument does
|
||||
# not trip `set -e`, so the inline form degrades silently to an
|
||||
# empty constant. VERSION is computed here because .dockerignore
|
||||
# excludes .git, so `git describe` in a build stage yields an empty
|
||||
# version without failing.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache \
|
||||
--build-arg VERSION="$version" \
|
||||
-t "$("$SCRIPT_DIR/projectname")" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
#!/bin/sh
|
||||
# script/frontend-check: run the frontend half of the checks only (test,
|
||||
# lint, fmt-check). This exists for the frontend Dockerfile, whose build
|
||||
# stage is a node image with neither Go nor Docker; the backend half is
|
||||
# gated by Dockerfile.backend. Everywhere else, use script/check, which
|
||||
# covers the whole repo. Must not modify any files.
|
||||
# lint, fmt-check). This exists for the frontend stage of Dockerfile, a
|
||||
# node image with neither Go nor Docker; the Dockerfile's lint and
|
||||
# backend build stages gate the backend half. Everywhere else, use
|
||||
# script/check, which covers the whole repo. Must not modify any files.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
|
||||
+3
-3
@@ -3,8 +3,8 @@
|
||||
# Go linter over backend/.
|
||||
#
|
||||
# The Go linter runs only in Docker: this builds the lint stage of
|
||||
# Dockerfile.backend, the digest-pinned golangci-lint image, which runs
|
||||
# the backend's fmt-check and lint targets. --no-cache makes the linter
|
||||
# Dockerfile, the digest-pinned golangci-lint image, which runs the
|
||||
# backend's fmt-check and lint targets. --no-cache makes the linter
|
||||
# really run every time rather than reuse an earlier result, and the
|
||||
# stage is built for its checks alone, so no image is kept.
|
||||
set -eu
|
||||
@@ -15,7 +15,7 @@ main() {
|
||||
cd "$ROOT"
|
||||
"$ROOT/script/frontend-lint"
|
||||
timeout 300 docker build --no-cache --target lint \
|
||||
--output type=cacheonly -f Dockerfile.backend .
|
||||
--output type=cacheonly .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user