Files
AFC-Demo/Dockerfile
T
2025-10-22 22:53:46 +02:00

158 lines
5.3 KiB
Docker
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# =========
# Stage 0: Frontend build (Vite)
# =========
FROM node:20-alpine AS nodebuild
WORKDIR /app
# Install JS deps first for caching
COPY package.json package-lock.json* pnpm-lock.yaml* yarn.lock* ./
RUN \
if [ -f package-lock.json ]; then npm ci; \
elif [ -f pnpm-lock.yaml ]; then corepack enable && pnpm i --frozen-lockfile; \
elif [ -f yarn.lock ]; then yarn install --frozen-lockfile; \
else npm i; fi
# Copy the rest and build
COPY . .
ENV NODE_ENV=production
# If your Vite build needs ASSET_URL or similar, set it here:
# ENV ASSET_URL=/
RUN \
if [ -f package.json ]; then \
if npm run | grep -q " build"; then npm run build; \
else echo "No build script in package.json"; fi; \
fi
# =========
# Stage 1: Composer / PHP deps
# =========
FROM php:8.4-fpm-alpine AS build
# Build dependencies for PHP extensions and composer operations
RUN set -eux; \
apk add --no-cache \
git unzip \
libzip-dev oniguruma-dev icu-dev \
autoconf build-base postgresql-dev
# PHP extensions (include PostgreSQL)
RUN docker-php-ext-configure zip; \
docker-php-ext-install -j"$(nproc)" \
pdo_mysql pdo_pgsql pgsql zip opcache intl
# Composer
ENV COMPOSER_ALLOW_SUPERUSER=1 COMPOSER_HOME=/tmp/composer
COPY --from=composer:2 /usr/bin/composer /usr/local/bin/composer
# Install PHP deps
WORKDIR /app
COPY composer.json composer.lock ./
RUN set -eux; \
composer install \
--no-dev --no-interaction --prefer-dist \
--optimize-autoloader --no-scripts
# Copy app source (do not run artisan optimize here; well clear/warmup at runtime if needed)
COPY . .
# =========
# Stage 2: Runtime (nginx + php-fpm)
# =========
FROM php:8.4-fpm-alpine
# Base runtime packages
RUN set -eux; \
apk add --no-cache \
nginx supervisor curl \
libzip icu-libs
# Build PHP runtime extensions (need *-dev to compile)
RUN set -eux; \
apk add --no-cache \
libzip-dev icu-dev oniguruma-dev postgresql-dev; \
docker-php-ext-configure zip; \
docker-php-ext-install -j"$(nproc)" \
pdo_mysql pdo_pgsql pgsql zip opcache intl; \
# PostgreSQL client runtime lib so pdo_pgsql/pgsql can load
apk add --no-cache libpq; \
# Remove build deps
apk del --no-progress --purge \
libzip-dev icu-dev oniguruma-dev postgresql-dev || true
# php.ini production + opcache tuning
RUN set -eux; \
mv "$PHP_INI_DIR/php.ini-production" "$PHP_INI_DIR/php.ini"; \
{ \
echo "opcache.enable=1"; \
echo "opcache.enable_cli=0"; \
echo "opcache.memory_consumption=128"; \
echo "opcache.max_accelerated_files=20000"; \
echo "opcache.validate_timestamps=0"; \
echo "realpath_cache_size=4096K"; \
echo "realpath_cache_ttl=600"; \
} >> "$PHP_INI_DIR/conf.d/99-opcache.ini"
# Configure PHP-FPM: pass env, listen on TCP, run as nginx
RUN set -eux; \
sed -ri 's|^;?clear_env\s*=.*|clear_env = no|g' /usr/local/etc/php-fpm.d/www.conf; \
sed -ri 's|^listen = .*|listen = 127.0.0.1:9000|g' /usr/local/etc/php-fpm.d/www.conf; \
sed -ri 's|^user\s*=.*|user = nginx|g' /usr/local/etc/php-fpm.d/www.conf; \
sed -ri 's|^group\s*=.*|group = nginx|g' /usr/local/etc/php-fpm.d/www.conf; \
{ \
echo "ping.path = /ping"; \
echo "pm.status_path = /status"; \
echo "catch_workers_output = yes"; \
} >> /usr/local/etc/php-fpm.d/www.conf
# Create required directories
RUN set -eux; \
mkdir -p /run/nginx /var/log/nginx /var/log/supervisor \
/etc/nginx/conf.d /var/www/html \
/var/cache/nginx /var/lib/nginx/tmp
# App code
WORKDIR /var/www/html
COPY --from=build --chown=nginx:nginx /app /var/www/html
# Copy built frontend assets from node stage
COPY --from=nodebuild --chown=nginx:nginx /app/public/build /var/www/html/public/build
# Nginx + Supervisor configs + health + entrypoint
# Ensure these files exist in your repo under ./docker
COPY ./docker/nginx.conf /etc/nginx/nginx.conf
COPY ./docker/site.conf /etc/nginx/conf.d/default.conf
COPY ./docker/supervisord.conf /etc/supervisord.conf
COPY ./docker/healthcheck.sh /usr/local/bin/healthcheck.sh
COPY ./docker/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/healthcheck.sh /usr/local/bin/entrypoint.sh
# Log to STDOUT/ERR
RUN set -eux; \
ln -sf /dev/stdout /var/log/nginx/access.log; \
ln -sf /dev/stderr /var/log/nginx/error.log
# Laravel writable dirs & permissions
RUN set -eux; \
mkdir -p storage/framework/{cache,sessions,views} storage/logs bootstrap/cache; \
chown -R nginx:nginx storage bootstrap/cache \
/var/cache/nginx /var/lib/nginx /var/lib/nginx/tmp \
/run/nginx /var/log/nginx /var/log/supervisor; \
chmod -R ug+rwX storage bootstrap/cache
# Optional: clear caches on container start via entrypoint (your entrypoint can do this)
# e.g., in /usr/local/bin/entrypoint.sh you might have:
# php artisan config:clear || true && php artisan cache:clear || true
# Env + port
ENV APP_ENV=production APP_DEBUG=false APP_URL=http://localhost APP_PORT=8080
EXPOSE 8080
# Healthcheck
HEALTHCHECK --interval=30s --timeout=5s --retries=3 CMD ["/usr/local/bin/healthcheck.sh"]
# Run as nginx user
USER nginx:nginx
# Launch supervisor (which can start php-fpm + nginx; your supervisord.conf should do that)
CMD ["/usr/bin/supervisord", "-c", "/etc/supervisord.conf"]