Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
96 lines (72 loc) · 2.9 KB
/
Copy pathDockerfile
File metadata and controls
96 lines (72 loc) · 2.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
# Using a 2-stage build. This is the builder for javascript frontend
FROM node:24 AS build
ENV YARN_VERSION=4.2.2
RUN yarn policies set-version $YARN_VERSION
RUN mkdir -p /app/frontend
WORKDIR /app/frontend
COPY frontend-v2/package.json /app/frontend
COPY frontend-v2/yarn.lock /app/frontend/
COPY frontend-v2/.yarnrc.yml /app/frontend/
COPY frontend-v2/.yarn /app/frontend/.yarn
RUN yarn install --immutable
COPY frontend-v2 /app/frontend/
COPY .env.prod /app/
COPY .env.prod /app/frontend/.env
# use git on the host to set REACT_APP_VERSION to the current git commit
ARG GIT_COMMIT_ID
ENV VITE_APP_VERSION=$GIT_COMMIT_ID
RUN yarn build
FROM python:3.12-bookworm
# install libsundials-dev
RUN apt-get update && apt-get upgrade -y
RUN apt-get install -y libsundials-dev memcached
# install nginx
RUN apt-get install nginx vim -y --no-install-recommends
RUN ln -sf /dev/stdout /var/log/nginx/access.log \
&& ln -sf /dev/stderr /var/log/nginx/error.log
RUN chown www-data:www-data /etc/nginx/sites-available/default
# install envsubst and git
RUN apt-get install -y gettext-base
# clean up apt
RUN apt-get clean
RUN apt-get autoclean
RUN apt-get autoremove
RUN rm -rf /var/lib/apt/lists/*
# install dependencies
COPY ./requirements.txt /
RUN apt-get update && apt-get upgrade -y
RUN apt-get install -y build-essential libsasl2-dev python3-dev libldap2-dev libssl-dev
RUN pip install -r requirements.txt
# install server code
WORKDIR /app
COPY ./pkpdapp .
RUN python manage.py collectstatic --noinput
# copy the built frontend (needs to be after we install nginx)
COPY --from=build /app/frontend/build /usr/share/nginx/html
# we're running as the www-data user, so make the files owned by this user
RUN chown -R www-data:www-data .
RUN chown -R www-data:www-data /usr/share/nginx/html
# make /var/www/.config dir and make it writable (myokit writes to it)
RUN mkdir -p /var/www/.config
RUN chown -R www-data:www-data /var/www
# gunicorn and nginx needs to write to a few places
RUN chown -R www-data:www-data /var/lib/nginx /run /tmp
# server setup files
COPY nginx.default.template .
COPY start-server.sh .
RUN chown -R www-data:www-data nginx.default.template start-server.sh
# run as www-data
USER www-data
# Defaults for the nginx template substitution. The manual-cert deploy reads
# certs from /etc/ssl/pkpdapp/ (a dedicated subdir so the mount can't clobber
# the system CA bundle at /etc/ssl/certs). The certbot deploy overrides
# SSL_CERT_PATH/SSL_KEY_PATH to the Let's Encrypt live paths. HOST_NAME has a
# default so an unset value can't render an invalid `server_name ;`.
ENV HOST_NAME=localhost
ENV SSL_CERT_PATH=/etc/ssl/pkpdapp/pkpdapp.crt
ENV SSL_KEY_PATH=/etc/ssl/pkpdapp/pkpdapp.key
# start-server.sh renders the nginx config from the template (via envsubst,
# resolving $PORT/$HOST_NAME/$SSL_CERT_PATH/$SSL_KEY_PATH from the container
# environment) and then launches the services.
STOPSIGNAL SIGTERM
CMD ["./start-server.sh"]