Multi-stage Dockerfile (deps -> build -> prod-deps -> runtime) that ships a full production node_modules rather than Next's standalone output, since standalone tracing is incompatible with a custom server (noted back in M1). Runs as a non-root user with a read-only rootfs, dropped capabilities, and tini as PID 1. tsx moves from dev to a real runtime dependency since the production start script runs server.ts directly rather than a precompiled bundle. next.config.ts marks dockerode/systeminformation as serverExternalPackages so Next's bundler leaves their OS-conditional requires alone. docker-compose.yml mirrors the sibling stacks' own conventions (TRAEFIK_HOST/NETWORK_NAME in .env, falcon_network as an external network, the same traefik.* label shape) so it fits their existing tooling, plus a new /api/health route and healthcheck.mjs for the container HEALTHCHECK. Verified end-to-end with a real `docker build` + `docker compose up`: non-root/read-only/cap-dropped container boots cleanly, is reachable by container name from another container on the shared network (as Traefik would reach it), and the container's own HEALTHCHECK reports healthy. That run surfaced a real gap - the non-root user got EACCES on /var/run/docker.sock, since it's owned by root:docker on the host - fixed via group_add on a DOCKER_GID env var (documented in .env.example with the command to find it), then re-verified that both docker.sock access and label-based auto-discovery work correctly under the fix.
21 lines
357 B
JavaScript
21 lines
357 B
JavaScript
import http from "node:http";
|
|
|
|
const req = http.request(
|
|
{
|
|
host: "127.0.0.1",
|
|
port: process.env.PORT || 3000,
|
|
path: "/api/health",
|
|
timeout: 3000,
|
|
},
|
|
(res) => {
|
|
process.exit(res.statusCode === 200 ? 0 : 1);
|
|
}
|
|
);
|
|
|
|
req.on("error", () => process.exit(1));
|
|
req.on("timeout", () => {
|
|
req.destroy();
|
|
process.exit(1);
|
|
});
|
|
req.end();
|