Dockerfile: deps -> builder -> runner. NEXT_PUBLIC_* vars are passed as
build args (inlined into the client bundle at build time, per Next.js);
everything else is read at container runtime instead (docker-compose.yml's
env_file / docker run --env-file) and never baked into an image layer.
Runner stage is non-root, ships only server.js + .next/static + public/
via output: "standalone".
Verified by actually running the build twice locally (Docker itself isn't
available in this environment) -- once with the real .env.local, once with
only placeholder values and no .env.local at all, matching the real Docker
build condition. The second run caught a real, pre-existing bug that had
nothing to do with Docker specifically: /login and three other
client-component trees (location/error, location/permission,
CategoryChips and NeighborhoodSearch nested in Server Component pages) all
call useSearchParams() without a Suspense boundary. next dev tolerates
this; next build hard-fails on it ("missing-suspense-with-csr-bailout").
This would have broken any production build -- Vercel, bare metal,
whatever -- not just Docker; fixed all four by wrapping in <Suspense>.
Also added .env.example (committed, no real values -- .env.local itself
stays gitignored) and a docker-compose.yml, with the --env-file .env.local
requirement called out explicitly in README.md since Compose only
auto-reads a file literally named .env, not .env.local.
59 lines
2.3 KiB
Docker
59 lines
2.3 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# ---- deps: install once, reused by the builder layer -----------------------
|
|
FROM node:24-alpine AS deps
|
|
WORKDIR /app
|
|
COPY package.json package-lock.json ./
|
|
RUN npm ci
|
|
|
|
# ---- builder: `next build` with output: "standalone" -----------------------
|
|
FROM node:24-alpine AS builder
|
|
WORKDIR /app
|
|
COPY --from=deps /app/node_modules ./node_modules
|
|
COPY . .
|
|
|
|
# NEXT_PUBLIC_* values are inlined into the client bundle at build time —
|
|
# there is no way to change them later, so they must be passed as build args
|
|
# (see docker-compose.yml, or `docker build --build-arg NEXT_PUBLIC_...=...`).
|
|
ARG NEXT_PUBLIC_GOOYAL_ACCOUNTS_BASE_URL
|
|
ARG NEXT_PUBLIC_GOOYAL_CLIENT_ID
|
|
ARG NEXT_PUBLIC_GOOYAL_CLIENT_SECRET
|
|
ARG NEXT_PUBLIC_GOOYAL_OAUTH_SCOPE
|
|
ENV NEXT_PUBLIC_GOOYAL_ACCOUNTS_BASE_URL=$NEXT_PUBLIC_GOOYAL_ACCOUNTS_BASE_URL \
|
|
NEXT_PUBLIC_GOOYAL_CLIENT_ID=$NEXT_PUBLIC_GOOYAL_CLIENT_ID \
|
|
NEXT_PUBLIC_GOOYAL_CLIENT_SECRET=$NEXT_PUBLIC_GOOYAL_CLIENT_SECRET \
|
|
NEXT_PUBLIC_GOOYAL_OAUTH_SCOPE=$NEXT_PUBLIC_GOOYAL_OAUTH_SCOPE
|
|
|
|
# Server-only vars are never read at build time (every route that touches them
|
|
# is dynamic — cookies()/no-store fetches — so nothing runs during
|
|
# prerendering), but a couple of modules validate them at import time
|
|
# (e.g. session.ts throws if SESSION_SECRET is missing), so the build still
|
|
# needs *some* value present. Real values are supplied at container runtime
|
|
# instead (see docker-compose.yml / `docker run --env-file`) — never bake a
|
|
# real secret into an image layer.
|
|
ENV WINOFY_API_BASE_URL=https://placeholder.invalid/api \
|
|
GOOYAL_ACCOUNTS_BASE_URL=https://placeholder.invalid \
|
|
GOOYAL_CLIENT_ID=placeholder \
|
|
GOOYAL_CLIENT_SECRET=placeholder \
|
|
GOOYAL_OAUTH_SCOPE=placeholder \
|
|
SESSION_SECRET=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=
|
|
|
|
RUN npm run build
|
|
|
|
# ---- runner: minimal production image ---------------------------------------
|
|
FROM node:24-alpine AS runner
|
|
WORKDIR /app
|
|
ENV NODE_ENV=production \
|
|
PORT=3000 \
|
|
HOSTNAME=0.0.0.0
|
|
|
|
RUN addgroup -g 1001 -S nodejs && adduser -S nextjs -u 1001
|
|
|
|
COPY --from=builder /app/public ./public
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
|
|
|
|
USER nextjs
|
|
EXPOSE 3000
|
|
|
|
CMD ["node", "server.js"]
|