[grade=B] DC-074+DC-091: Multi-stage Dockerfile + Dependabot config
DC-074: Multi-stage Dockerfile — builder stage installs all deps, production stage copies only node_modules + source. Reduces image size by excluding devDependencies from the final image. DC-091: .github/dependabot.yml — weekly npm + GitHub Actions dependency updates. Groups dev vs production deps separately, limits to 5 open PRs. All 1540 tests pass.
This commit is contained in:
@@ -0,0 +1,36 @@
|
|||||||
|
version: 2
|
||||||
|
updates:
|
||||||
|
- package-ecosystem: "npm"
|
||||||
|
directory: "/dashcaddy-api"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
open-pull-requests-limit: 5
|
||||||
|
labels:
|
||||||
|
- "dependencies"
|
||||||
|
- "automated"
|
||||||
|
groups:
|
||||||
|
dev-dependencies:
|
||||||
|
patterns:
|
||||||
|
- "jest"
|
||||||
|
- "eslint"
|
||||||
|
- "supertest"
|
||||||
|
update-types:
|
||||||
|
- "minor"
|
||||||
|
- "patch"
|
||||||
|
production-dependencies:
|
||||||
|
patterns:
|
||||||
|
- "*"
|
||||||
|
exclude-patterns:
|
||||||
|
- "jest"
|
||||||
|
- "eslint"
|
||||||
|
- "supertest"
|
||||||
|
update-types:
|
||||||
|
- "patch"
|
||||||
|
|
||||||
|
- package-ecosystem: "github-actions"
|
||||||
|
directory: "/"
|
||||||
|
schedule:
|
||||||
|
interval: "weekly"
|
||||||
|
labels:
|
||||||
|
- "dependencies"
|
||||||
|
- "automated"
|
||||||
@@ -1,3 +1,12 @@
|
|||||||
|
# ── Build stage: install all deps (including devDeps for build tooling) ──────
|
||||||
|
FROM node:20.11.1-alpine3.19 AS builder
|
||||||
|
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
COPY package*.json ./
|
||||||
|
RUN npm install
|
||||||
|
|
||||||
|
# ── Production stage: only production deps + source ──────────────────────────
|
||||||
FROM node:20.11.1-alpine3.19
|
FROM node:20.11.1-alpine3.19
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
@@ -5,17 +14,16 @@ WORKDIR /app
|
|||||||
# Install OpenSSL for certificate generation
|
# Install OpenSSL for certificate generation
|
||||||
RUN apk add --no-cache openssl
|
RUN apk add --no-cache openssl
|
||||||
|
|
||||||
COPY package*.json ./
|
# Copy production dependencies from builder
|
||||||
RUN npm install --production
|
COPY --from=builder /app/node_modules ./node_modules
|
||||||
|
|
||||||
|
# Copy application source
|
||||||
COPY *.js ./
|
COPY *.js ./
|
||||||
COPY src/ ./src/
|
COPY src/ ./src/
|
||||||
COPY routes/ ./routes/
|
COPY routes/ ./routes/
|
||||||
COPY openapi.yaml ./
|
COPY openapi.yaml ./
|
||||||
|
|
||||||
# VERSION file holds the short git SHA the image was built from. Committed as
|
# VERSION file holds the short git SHA the image was built from.
|
||||||
# 'dev' for source builds; the release script (scripts/release.sh) overwrites it
|
|
||||||
# with the actual commit hash before tarballing each release.
|
|
||||||
COPY VERSION ./
|
COPY VERSION ./
|
||||||
|
|
||||||
# Note: Running as root because container needs Docker socket access
|
# Note: Running as root because container needs Docker socket access
|
||||||
|
|||||||
Reference in New Issue
Block a user