2025-10-28 22:49:08 -04:00
|
|
|
# Multi-stage build for Next.js application
|
|
|
|
|
FROM node:20-alpine AS base
|
|
|
|
|
|
|
|
|
|
# Install dependencies only when needed
|
|
|
|
|
FROM base AS deps
|
|
|
|
|
RUN apk add --no-cache libc6-compat
|
|
|
|
|
WORKDIR /app
|
|
|
|
|
|
|
|
|
|
# Copy package files
|
|
|
|
|
COPY package.json package-lock.json* ./
|
|
|
|
|
RUN npm ci
|
|
|
|
|
|
|
|
|
|
# Rebuild the source code only when needed
|
|
|
|
|
FROM base AS builder
|
|
|
|
|
WORKDIR /app
|
|
|
|
|
COPY --from=deps /app/node_modules ./node_modules
|
|
|
|
|
COPY . .
|
|
|
|
|
|
|
|
|
|
# Next.js collects completely anonymous telemetry data about general usage.
|
|
|
|
|
# Learn more here: https://nextjs.org/telemetry
|
|
|
|
|
# Uncomment the following line in case you want to disable telemetry during the build.
|
|
|
|
|
ENV NEXT_TELEMETRY_DISABLED 1
|
|
|
|
|
|
|
|
|
|
RUN npm run build
|
|
|
|
|
|
2026-08-05 23:33:19 -04:00
|
|
|
# Download Bitwarden Secrets Manager CLI
|
|
|
|
|
FROM base AS bws
|
|
|
|
|
ARG BWS_VERSION=2.1.0
|
|
|
|
|
ARG BWS_ARCH=x86_64-unknown-linux-musl
|
|
|
|
|
RUN apk add --no-cache curl unzip
|
|
|
|
|
RUN curl -fsSL "https://github.com/bitwarden/sdk-sm/releases/download/bws-v${BWS_VERSION}/bws-${BWS_ARCH}-${BWS_VERSION}.zip" -o /tmp/bws.zip && \
|
|
|
|
|
mkdir -p /tmp/bws-extract && \
|
|
|
|
|
unzip -q /tmp/bws.zip -d /tmp/bws-extract && \
|
|
|
|
|
find /tmp/bws-extract -type f -name bws -exec chmod +x {} \; -exec cp {} /usr/local/bin/bws \; && \
|
|
|
|
|
/usr/local/bin/bws --version
|
|
|
|
|
|
2025-10-28 22:49:08 -04:00
|
|
|
# Production image, copy all the files and run next
|
|
|
|
|
FROM base AS runner
|
|
|
|
|
WORKDIR /app
|
|
|
|
|
|
|
|
|
|
ENV NODE_ENV production
|
|
|
|
|
ENV NEXT_TELEMETRY_DISABLED 1
|
|
|
|
|
|
|
|
|
|
RUN addgroup --system --gid 1001 nodejs
|
|
|
|
|
RUN adduser --system --uid 1001 nextjs
|
|
|
|
|
|
|
|
|
|
COPY --from=builder /app/public ./public
|
|
|
|
|
|
|
|
|
|
# Set the correct permission for prerender cache
|
|
|
|
|
RUN mkdir .next
|
|
|
|
|
RUN chown nextjs:nodejs .next
|
|
|
|
|
|
|
|
|
|
# Automatically leverage output traces to reduce image size
|
|
|
|
|
# https://nextjs.org/docs/advanced-features/output-file-tracing
|
|
|
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
|
|
|
|
|
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
|
|
|
|
|
|
2026-08-05 23:33:19 -04:00
|
|
|
# Copy Bitwarden Secrets Manager CLI and entrypoint
|
|
|
|
|
COPY --from=bws /usr/local/bin/bws /usr/local/bin/bws
|
|
|
|
|
COPY docker-entrypoint.sh /app/docker-entrypoint.sh
|
|
|
|
|
RUN chmod +x /app/docker-entrypoint.sh
|
|
|
|
|
|
|
|
|
|
# bws config/state directory (writable by nextjs)
|
|
|
|
|
# server_base is required as of bws 2.x — the profile errors with
|
|
|
|
|
# "Profile has no `server_base` or `server_identity`" without it, even
|
|
|
|
|
# for the default Bitwarden cloud instance.
|
|
|
|
|
RUN mkdir -p /app/.config/bws && chown -R nextjs:nodejs /app/.config/bws && \
|
|
|
|
|
printf '[profiles.default]\nserver_base = "https://vault.bitwarden.com"\nstate_dir = "/app/.config/bws/state"\n' > /app/.config/bws/config && \
|
|
|
|
|
chown nextjs:nodejs /app/.config/bws/config
|
|
|
|
|
ENV BWS_CONFIG_FILE=/app/.config/bws/config
|
|
|
|
|
|
2025-10-28 22:49:08 -04:00
|
|
|
USER nextjs
|
|
|
|
|
|
|
|
|
|
# Use custom port 3100 instead of 3000
|
|
|
|
|
EXPOSE 3100
|
|
|
|
|
|
|
|
|
|
ENV PORT 3100
|
|
|
|
|
ENV HOSTNAME "0.0.0.0"
|
|
|
|
|
|
2026-08-05 23:33:19 -04:00
|
|
|
CMD ["/app/docker-entrypoint.sh"]
|