Files
FlowReader/Dockerfile
Antigravity AgentandClaude Opus 5.5 9eaed0aea4 chore(deploy): non-root image, reproducible builds, private database
- Dockerfile: Go 1.26, npm ci, go mod verify, non-root user, alpine 3.22.
- Compose: Postgres no longer published on the host, password and new
  security settings read from .env, GOMEMLIMIT.
- README: document new environment variables and reading shortcuts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 07:34:09 +02:00

34 lines
923 B
Docker

# Multi-stage Dockerfile for FlowReader
# Step 1: Build the React Frontend
FROM node:22-alpine AS web-builder
WORKDIR /app/web
COPY web/package*.json ./
# Reproducible install from the lockfile
RUN npm ci --no-audit --no-fund
COPY web/ ./
RUN npm run build
# Step 2: Build the Go Backend
FROM golang:1.26-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download && go mod verify
COPY cmd/ ./cmd/
COPY internal/ ./internal/
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-w -s" -o /server ./cmd/server
# Step 3: Final Production Image
FROM alpine:3.22
WORKDIR /app
RUN apk add --no-cache wget ca-certificates tzdata \
&& adduser -D -H -u 10001 flowreader
COPY --from=builder /server /app/server
# Static frontend and migrations (read-only for the app user)
COPY --from=web-builder /app/web/dist /app/web/dist
COPY migrations /app/migrations
USER flowreader
EXPOSE 8080
CMD ["/app/server"]