[grade=B] DC-074+DC-091: Multi-stage Dockerfile + Dependabot config
DC-074: Multi-stage Dockerfile — builder stage installs all deps, production stage copies only node_modules + source. Reduces image size by excluding devDependencies from the final image. DC-091: .github/dependabot.yml — weekly npm + GitHub Actions dependency updates. Groups dev vs production deps separately, limits to 5 open PRs. All 1540 tests pass.
This commit is contained in:
@@ -1,3 +1,12 @@
|
||||
# ── Build stage: install all deps (including devDeps for build tooling) ──────
|
||||
FROM node:20.11.1-alpine3.19 AS builder
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
COPY package*.json ./
|
||||
RUN npm install
|
||||
|
||||
# ── Production stage: only production deps + source ──────────────────────────
|
||||
FROM node:20.11.1-alpine3.19
|
||||
|
||||
WORKDIR /app
|
||||
@@ -5,17 +14,16 @@ WORKDIR /app
|
||||
# Install OpenSSL for certificate generation
|
||||
RUN apk add --no-cache openssl
|
||||
|
||||
COPY package*.json ./
|
||||
RUN npm install --production
|
||||
# Copy production dependencies from builder
|
||||
COPY --from=builder /app/node_modules ./node_modules
|
||||
|
||||
# Copy application source
|
||||
COPY *.js ./
|
||||
COPY src/ ./src/
|
||||
COPY routes/ ./routes/
|
||||
COPY openapi.yaml ./
|
||||
|
||||
# VERSION file holds the short git SHA the image was built from. Committed as
|
||||
# 'dev' for source builds; the release script (scripts/release.sh) overwrites it
|
||||
# with the actual commit hash before tarballing each release.
|
||||
# VERSION file holds the short git SHA the image was built from.
|
||||
COPY VERSION ./
|
||||
|
||||
# Note: Running as root because container needs Docker socket access
|
||||
|
||||
Reference in New Issue
Block a user