optimize docckerfile
This commit is contained in:
36
Dockerfile
36
Dockerfile
@@ -1,14 +1,38 @@
|
|||||||
FROM node:lts AS build
|
# Build stage
|
||||||
|
FROM node:lts-alpine AS build
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Copy package files first to leverage cache
|
# Install dependencies first to leverage Docker cache
|
||||||
COPY package*.json ./
|
COPY package*.json ./
|
||||||
RUN npm ci
|
RUN npm ci --no-audit --no-fund --production && \
|
||||||
|
npm cache clean --force
|
||||||
|
|
||||||
# Copy remaining files
|
# Copy source code and build
|
||||||
COPY . .
|
COPY . .
|
||||||
RUN npm run build
|
RUN npm run build
|
||||||
|
|
||||||
FROM httpd:2.4 AS runtime
|
# Runtime stage
|
||||||
|
FROM httpd:2.4-alpine AS runtime
|
||||||
|
|
||||||
|
# Copy custom httpd config if needed
|
||||||
|
# COPY ./httpd.conf /usr/local/apache2/conf/httpd.conf
|
||||||
|
|
||||||
|
# Copy built assets from build stage
|
||||||
COPY --from=build /app/dist /usr/local/apache2/htdocs/
|
COPY --from=build /app/dist /usr/local/apache2/htdocs/
|
||||||
EXPOSE 80
|
|
||||||
|
# Add security headers
|
||||||
|
RUN echo 'Header set X-Content-Type-Options "nosniff"' >> /usr/local/apache2/conf/httpd.conf && \
|
||||||
|
echo 'Header set X-Frame-Options "SAMEORIGIN"' >> /usr/local/apache2/conf/httpd.conf && \
|
||||||
|
echo 'Header set X-XSS-Protection "1; mode=block"' >> /usr/local/apache2/conf/httpd.conf
|
||||||
|
|
||||||
|
# Use non-root user for better security
|
||||||
|
RUN adduser -D -H -u 1000 appuser && \
|
||||||
|
chown -R appuser:appuser /usr/local/apache2/htdocs/
|
||||||
|
|
||||||
|
USER appuser
|
||||||
|
|
||||||
|
EXPOSE 80
|
||||||
|
|
||||||
|
# Health check
|
||||||
|
HEALTHCHECK --interval=30s --timeout=3s \
|
||||||
|
CMD wget --quiet --tries=1 --spider http://localhost:80/ || exit 1
|
||||||
Reference in New Issue
Block a user