mirror of
https://github.com/penpot/penpot.git
synced 2026-08-01 18:11:23 -04:00
Move Dockerfile.frontend, .backend, .exporter, .mcp and .storybook under docker/images/ from ubuntu:26.04 / nginx-unprivileged / a manual Node tarball install to Docker Hardened Images (Debian 13, or Alpine for storybook). storybook and mcp get a true non-dev runtime; frontend, backend and exporter keep the -dev tag as their final image, since each needs a shell and/or package manager at container runtime (nginx templating, fontforge/python3, and a headless-browser stack, respectively).
44 lines
1.8 KiB
Docker
44 lines
1.8 KiB
Docker
FROM dhi.io/nginx:1.31.1-debian13-dev
|
|
LABEL maintainer="Penpot <docker@penpot.app>"
|
|
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
|
|
USER root
|
|
|
|
RUN set -ex; \
|
|
apt-get -qq update; \
|
|
apt-get -qq -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" dist-upgrade; \
|
|
apt-get -qqy -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" --no-install-recommends install bash gettext-base passwd; \
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
groupadd -f -g 1001 penpot; \
|
|
useradd -M -u 1001 -s /usr/sbin/nologin -d /opt/penpot -g penpot penpot; \
|
|
mkdir -p /opt/data/assets; \
|
|
chown -R penpot:penpot /opt/data; \
|
|
mkdir -p /etc/nginx/overrides/main.d/; \
|
|
mkdir -p /etc/nginx/overrides/http.d/; \
|
|
mkdir -p /etc/nginx/overrides/server.d/; \
|
|
mkdir -p /etc/nginx/overrides/assets.d/; \
|
|
mkdir -p /etc/nginx/overrides/location.d/;
|
|
|
|
ARG BUNDLE_PATH="./bundle-frontend/"
|
|
COPY $BUNDLE_PATH /var/www/app/
|
|
COPY ./files/config.js /var/www/app/js/config.js
|
|
COPY ./files/nginx.conf.template /tmp/nginx.conf.template
|
|
COPY ./files/nginx-resolvers.conf.template /tmp/resolvers.conf.template
|
|
COPY ./files/nginx-mcp-locations.conf.template /tmp/nginx-mcp-locations.conf.template
|
|
COPY ./files/nginx-security-headers.conf /etc/nginx/nginx-security-headers.conf
|
|
COPY ./files/nginx-mime.types /etc/nginx/mime.types
|
|
COPY ./files/nginx-external-locations.conf /etc/nginx/overrides/location.d/external-locations.conf
|
|
COPY ./files/nginx-entrypoint.sh /entrypoint.sh
|
|
|
|
RUN chown -R 1001:0 /var/cache/nginx; \
|
|
chmod -R g+w /var/cache/nginx; \
|
|
chown -R 1001:0 /etc/nginx; \
|
|
chmod -R g+w /etc/nginx; \
|
|
chown -R 1001:0 /var/www; \
|
|
chmod -R g+w /var/www;
|
|
|
|
USER penpot:penpot
|
|
ENTRYPOINT ["/bin/bash", "/entrypoint.sh"]
|
|
CMD ["nginx", "-g", "daemon off;"]
|