feat: streamline Docker builds with .dockerignore and pass NPM_TOKEN as a build secret for pnpm install.
This commit is contained in:
12
.dockerignore
Normal file
12
.dockerignore
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
node_modules
|
||||||
|
.next
|
||||||
|
.git
|
||||||
|
.npmrc
|
||||||
|
dist
|
||||||
|
build
|
||||||
|
out
|
||||||
|
coverage
|
||||||
|
.vercel
|
||||||
|
.turbo
|
||||||
|
*.log
|
||||||
|
.DS_Store
|
||||||
@@ -106,6 +106,8 @@ jobs:
|
|||||||
file: packages/infra/docker/Dockerfile.nextjs
|
file: packages/infra/docker/Dockerfile.nextjs
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
push: true
|
push: true
|
||||||
|
secrets: |
|
||||||
|
NPM_TOKEN=${{ secrets.NPM_TOKEN }}
|
||||||
tags: |
|
tags: |
|
||||||
registry.infra.mintel.me/mintel/nextjs:${{ github.ref_name }}
|
registry.infra.mintel.me/mintel/nextjs:${{ github.ref_name }}
|
||||||
registry.infra.mintel.me/mintel/nextjs:latest
|
registry.infra.mintel.me/mintel/nextjs:latest
|
||||||
@@ -117,6 +119,8 @@ jobs:
|
|||||||
file: packages/infra/docker/Dockerfile.runtime
|
file: packages/infra/docker/Dockerfile.runtime
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
push: true
|
push: true
|
||||||
|
secrets: |
|
||||||
|
NPM_TOKEN=${{ secrets.NPM_TOKEN }}
|
||||||
tags: |
|
tags: |
|
||||||
registry.infra.mintel.me/mintel/runtime:${{ github.ref_name }}
|
registry.infra.mintel.me/mintel/runtime:${{ github.ref_name }}
|
||||||
registry.infra.mintel.me/mintel/runtime:latest
|
registry.infra.mintel.me/mintel/runtime:latest
|
||||||
@@ -128,6 +132,8 @@ jobs:
|
|||||||
file: packages/infra/docker/Dockerfile.gatekeeper
|
file: packages/infra/docker/Dockerfile.gatekeeper
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
push: true
|
push: true
|
||||||
|
secrets: |
|
||||||
|
NPM_TOKEN=${{ secrets.NPM_TOKEN }}
|
||||||
tags: |
|
tags: |
|
||||||
registry.infra.mintel.me/mintel/gatekeeper:${{ github.ref_name }}
|
registry.infra.mintel.me/mintel/gatekeeper:${{ github.ref_name }}
|
||||||
registry.infra.mintel.me/mintel/gatekeeper:latest
|
registry.infra.mintel.me/mintel/gatekeeper:latest
|
||||||
@@ -139,6 +145,8 @@ jobs:
|
|||||||
file: packages/infra/docker/Dockerfile.directus
|
file: packages/infra/docker/Dockerfile.directus
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
push: true
|
push: true
|
||||||
|
secrets: |
|
||||||
|
NPM_TOKEN=${{ secrets.NPM_TOKEN }}
|
||||||
tags: |
|
tags: |
|
||||||
registry.infra.mintel.me/mintel/directus:${{ github.ref_name }}
|
registry.infra.mintel.me/mintel/directus:${{ github.ref_name }}
|
||||||
registry.infra.mintel.me/mintel/directus:latest
|
registry.infra.mintel.me/mintel/directus:latest
|
||||||
|
|||||||
@@ -6,15 +6,15 @@ WORKDIR /app
|
|||||||
# Enable pnpm
|
# Enable pnpm
|
||||||
RUN corepack enable pnpm
|
RUN corepack enable pnpm
|
||||||
|
|
||||||
# Install dependencies (using monorepo root context)
|
# Step 2: Install dependencies
|
||||||
COPY pnpm-lock.yaml pnpm-workspace.yaml package.json .npmrc* ./
|
# We copy everything first because we have a .dockerignore
|
||||||
COPY packages/gatekeeper/package.json ./packages/gatekeeper/
|
# and we need the workspace structure for pnpm to work correctly
|
||||||
COPY packages/next-utils/package.json ./packages/next-utils/
|
COPY . .
|
||||||
COPY packages/tsconfig/package.json ./packages/tsconfig/
|
|
||||||
COPY packages/eslint-config/package.json ./packages/eslint-config/
|
|
||||||
COPY packages/next-config/package.json ./packages/next-config/
|
|
||||||
|
|
||||||
|
# Use a secret for NPM_TOKEN to authenticate with private registry
|
||||||
RUN --mount=type=cache,target=/root/.local/share/pnpm/store/v3 \
|
RUN --mount=type=cache,target=/root/.local/share/pnpm/store/v3 \
|
||||||
|
--mount=type=secret,id=NPM_TOKEN \
|
||||||
|
export NPM_TOKEN=$(cat /run/secrets/NPM_TOKEN) && \
|
||||||
pnpm i --frozen-lockfile
|
pnpm i --frozen-lockfile
|
||||||
|
|
||||||
# Copy source
|
# Copy source
|
||||||
|
|||||||
@@ -1,24 +1,19 @@
|
|||||||
|
# Step 1: Base image
|
||||||
FROM node:20-alpine AS base
|
FROM node:20-alpine AS base
|
||||||
|
|
||||||
RUN apk add --no-cache libc6-compat curl
|
RUN apk add --no-cache libc6-compat curl
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Enable pnpm
|
|
||||||
RUN corepack enable pnpm
|
RUN corepack enable pnpm
|
||||||
|
|
||||||
# Copy root configurations
|
# Step 2: Install dependencies
|
||||||
COPY pnpm-lock.yaml pnpm-workspace.yaml package.json .npmrc* ./
|
# We copy everything first because we have a .dockerignore
|
||||||
|
# and we need the workspace structure for pnpm to work correctly
|
||||||
# Copy all package.json files to allow pnpm install to be cached
|
|
||||||
COPY packages/*/package.json ./packages/
|
|
||||||
COPY apps/*/package.json ./apps/
|
|
||||||
|
|
||||||
# Install dependencies for the entire monorepo
|
|
||||||
RUN --mount=type=cache,target=/root/.local/share/pnpm/store/v3 \
|
|
||||||
pnpm i --frozen-lockfile
|
|
||||||
|
|
||||||
# Copy the rest of the source code
|
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
# Post-install/Build shared packages if needed
|
# Use a secret for NPM_TOKEN to authenticate with private registry
|
||||||
|
RUN --mount=type=cache,target=/root/.local/share/pnpm/store/v3 \
|
||||||
|
--mount=type=secret,id=NPM_TOKEN \
|
||||||
|
export NPM_TOKEN=$(cat /run/secrets/NPM_TOKEN) && \
|
||||||
|
pnpm i --frozen-lockfile
|
||||||
|
|
||||||
|
# Step 3: Build shared packages
|
||||||
RUN pnpm -r build --filter="./packages/*"
|
RUN pnpm -r build --filter="./packages/*"
|
||||||
|
|||||||
@@ -199,6 +199,8 @@ jobs:
|
|||||||
NEXT_PUBLIC_BASE_URL=${{ needs.prepare.outputs.next_public_base_url }}
|
NEXT_PUBLIC_BASE_URL=${{ needs.prepare.outputs.next_public_base_url }}
|
||||||
NEXT_PUBLIC_TARGET=${{ needs.prepare.outputs.target }}
|
NEXT_PUBLIC_TARGET=${{ needs.prepare.outputs.target }}
|
||||||
push: true
|
push: true
|
||||||
|
secrets: |
|
||||||
|
NPM_TOKEN=${{ secrets.NPM_TOKEN }}
|
||||||
tags: registry.infra.mintel.me/mintel/${{ github.event.repository.name }}:${{ needs.prepare.outputs.image_tag }}
|
tags: registry.infra.mintel.me/mintel/${{ github.event.repository.name }}:${{ needs.prepare.outputs.image_tag }}
|
||||||
cache-from: type=registry,ref=registry.infra.mintel.me/mintel/${{ github.event.repository.name }}:buildcache
|
cache-from: type=registry,ref=registry.infra.mintel.me/mintel/${{ github.event.repository.name }}:buildcache
|
||||||
cache-to: type=registry,ref=registry.infra.mintel.me/mintel/${{ github.event.repository.name }}:buildcache,mode=max
|
cache-to: type=registry,ref=registry.infra.mintel.me/mintel/${{ github.event.repository.name }}:buildcache,mode=max
|
||||||
|
|||||||
Reference in New Issue
Block a user