From bbcc7d159cb47fa7431abe125b3645607acc87e5 Mon Sep 17 00:00:00 2001 From: Marc Mintel Date: Thu, 9 Apr 2026 22:26:57 +0200 Subject: [PATCH] fix(deploy): resolve permission issues and stabilize asset build context --- .gitea/workflows/deploy.yml | 1 + Dockerfile | 12 ++++++++++++ 2 files changed, 13 insertions(+) diff --git a/.gitea/workflows/deploy.yml b/.gitea/workflows/deploy.yml index f8c6d3b..fae0471 100644 --- a/.gitea/workflows/deploy.yml +++ b/.gitea/workflows/deploy.yml @@ -316,6 +316,7 @@ jobs: S3_BUCKET=${{ secrets.S3_BUCKET || vars.S3_BUCKET || 'mintel' }} S3_REGION=${{ secrets.S3_REGION || vars.S3_REGION || 'fsn1' }} S3_PREFIX=${{ secrets.S3_PREFIX || vars.S3_PREFIX || 'mintel.me' }} + BUILD_ID=${{ github.sha }} tags: registry.infra.mintel.me/mintel/mintel.me:${{ needs.prepare.outputs.image_tag }} cache-from: type=registry,ref=registry.infra.mintel.me/mintel/mintel.me:buildcache-${{ needs.prepare.outputs.target }} cache-to: type=registry,ref=registry.infra.mintel.me/mintel/mintel.me:buildcache-${{ needs.prepare.outputs.target }},mode=max diff --git a/Dockerfile b/Dockerfile index c3217c8..85fbeac 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,6 +13,7 @@ ARG S3_SECRET_KEY ARG S3_BUCKET ARG S3_REGION ARG S3_PREFIX +ARG BUILD_ID # Environment variables for Next.js build ENV NEXT_PUBLIC_BASE_URL=$NEXT_PUBLIC_BASE_URL @@ -47,6 +48,10 @@ RUN --mount=type=cache,id=pnpm,target=/pnpm/store \ rm .npmrc # Copy source code +# We use BUILD_ID here to ensure that if the commit changes, we always COPY the latest files +# even if Docker's metadata-based fingerprinting for the public directory fails. +ARG BUILD_ID +RUN echo "Building with ID: ${BUILD_ID}" COPY . . # Build application (monorepo filter) @@ -65,6 +70,13 @@ COPY --from=builder /app/apps/web/.next/static ./apps/web/.next/static # Explicitly copy Payload dynamically generated importMap.js excluded by Standalone tracing COPY --from=builder /app/apps/web/app/(payload)/admin/importMap.js ./apps/web/app/(payload)/admin/importMap.js + +# Fix permissions for the non-root user (Standard uid/gid from base image) +# We do this as root before switching users +USER root +RUN chown -R 1001:65533 /app +USER nextjs + # Start from the app directory to ensure references solve correctly WORKDIR /app/apps/web CMD ["node", "server.js"]