# ========= # Stage 0: Frontend build (Vite) # ========= FROM node:20-alpine AS nodebuild WORKDIR /app # Install JS deps first for caching COPY package.json package-lock.json* pnpm-lock.yaml* yarn.lock* ./ RUN \ if [ -f package-lock.json ]; then npm ci; \ elif [ -f pnpm-lock.yaml ]; then corepack enable && pnpm i --frozen-lockfile; \ elif [ -f yarn.lock ]; then yarn install --frozen-lockfile; \ else npm i; fi # Copy the rest and build COPY . . ENV NODE_ENV=production # If your Vite build needs ASSET_URL or similar, set it here: # ENV ASSET_URL=/ RUN \ if [ -f package.json ]; then \ if npm run | grep -q " build"; then npm run build; \ else echo "No build script in package.json"; fi; \ fi # ========= # Stage 1: Composer / PHP deps # ========= FROM php:8.4-fpm-alpine AS build # Build dependencies for PHP extensions and composer operations RUN set -eux; \ apk add --no-cache \ git unzip \ libzip-dev oniguruma-dev icu-dev \ autoconf build-base postgresql-dev # PHP extensions (include PostgreSQL) RUN docker-php-ext-configure zip; \ docker-php-ext-install -j"$(nproc)" \ pdo_mysql pdo_pgsql pgsql zip opcache intl # Composer ENV COMPOSER_ALLOW_SUPERUSER=1 COMPOSER_HOME=/tmp/composer COPY --from=composer:2 /usr/bin/composer /usr/local/bin/composer # Install PHP deps WORKDIR /app COPY composer.json composer.lock ./ RUN set -eux; \ composer install \ --no-dev --no-interaction --prefer-dist \ --optimize-autoloader --no-scripts # Copy app source (do not run artisan optimize here; we’ll clear/warmup at runtime if needed) COPY . . # ========= # Stage 2: Runtime (nginx + php-fpm) # ========= FROM php:8.4-fpm-alpine # Base runtime packages RUN set -eux; \ apk add --no-cache \ nginx supervisor curl \ libzip icu-libs # Build PHP runtime extensions (need *-dev to compile) RUN set -eux; \ apk add --no-cache \ libzip-dev icu-dev oniguruma-dev postgresql-dev; \ docker-php-ext-configure zip; \ docker-php-ext-install -j"$(nproc)" \ pdo_mysql pdo_pgsql pgsql zip opcache intl; \ # PostgreSQL client runtime lib so pdo_pgsql/pgsql can load apk add --no-cache libpq; \ # Remove build deps apk del --no-progress --purge \ libzip-dev icu-dev oniguruma-dev postgresql-dev || true # php.ini production + opcache tuning RUN set -eux; \ mv "$PHP_INI_DIR/php.ini-production" "$PHP_INI_DIR/php.ini"; \ { \ echo "opcache.enable=1"; \ echo "opcache.enable_cli=0"; \ echo "opcache.memory_consumption=128"; \ echo "opcache.max_accelerated_files=20000"; \ echo "opcache.validate_timestamps=0"; \ echo "realpath_cache_size=4096K"; \ echo "realpath_cache_ttl=600"; \ } >> "$PHP_INI_DIR/conf.d/99-opcache.ini" # Configure PHP-FPM: pass env, listen on TCP, run as nginx RUN set -eux; \ sed -ri 's|^;?clear_env\s*=.*|clear_env = no|g' /usr/local/etc/php-fpm.d/www.conf; \ sed -ri 's|^listen = .*|listen = 127.0.0.1:9000|g' /usr/local/etc/php-fpm.d/www.conf; \ sed -ri 's|^user\s*=.*|user = nginx|g' /usr/local/etc/php-fpm.d/www.conf; \ sed -ri 's|^group\s*=.*|group = nginx|g' /usr/local/etc/php-fpm.d/www.conf; \ { \ echo "ping.path = /ping"; \ echo "pm.status_path = /status"; \ echo "catch_workers_output = yes"; \ } >> /usr/local/etc/php-fpm.d/www.conf # Create required directories RUN set -eux; \ mkdir -p /run/nginx /var/log/nginx /var/log/supervisor \ /etc/nginx/conf.d /var/www/html \ /var/cache/nginx /var/lib/nginx/tmp # App code WORKDIR /var/www/html COPY --from=build --chown=nginx:nginx /app /var/www/html # Copy built frontend assets from node stage COPY --from=nodebuild --chown=nginx:nginx /app/public/build /var/www/html/public/build # Nginx + Supervisor configs + health + entrypoint # Ensure these files exist in your repo under ./docker COPY ./docker/nginx.conf /etc/nginx/nginx.conf COPY ./docker/site.conf /etc/nginx/conf.d/default.conf COPY ./docker/supervisord.conf /etc/supervisord.conf COPY ./docker/healthcheck.sh /usr/local/bin/healthcheck.sh COPY ./docker/entrypoint.sh /usr/local/bin/entrypoint.sh RUN chmod +x /usr/local/bin/healthcheck.sh /usr/local/bin/entrypoint.sh # Log to STDOUT/ERR RUN set -eux; \ ln -sf /dev/stdout /var/log/nginx/access.log; \ ln -sf /dev/stderr /var/log/nginx/error.log # Laravel writable dirs & permissions RUN set -eux; \ mkdir -p storage/framework/{cache,sessions,views} storage/logs bootstrap/cache; \ chown -R nginx:nginx storage bootstrap/cache \ /var/cache/nginx /var/lib/nginx /var/lib/nginx/tmp \ /run/nginx /var/log/nginx /var/log/supervisor; \ chmod -R ug+rwX storage bootstrap/cache # Optional: clear caches on container start via entrypoint (your entrypoint can do this) # e.g., in /usr/local/bin/entrypoint.sh you might have: # php artisan config:clear || true && php artisan cache:clear || true # Env + port ENV APP_ENV=production APP_DEBUG=false APP_URL=http://localhost APP_PORT=8080 EXPOSE 8080 # Healthcheck HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/usr/local/bin/healthcheck.sh"] # Run as nginx user USER nginx:nginx # Launch supervisor (which can start php-fpm + nginx; your supervisord.conf should do that) CMD ["/usr/bin/supervisord", "-c", "/etc/supervisord.conf"]