# Multi-stage build for Next.js application FROM node:20-alpine AS base # Install dependencies only when needed FROM base AS deps RUN apk add --no-cache libc6-compat WORKDIR /app # Copy package files COPY package.json package-lock.json* ./ RUN npm ci # Rebuild the source code only when needed FROM base AS builder WORKDIR /app COPY --from=deps /app/node_modules ./node_modules COPY . . # Next.js collects completely anonymous telemetry data about general usage. # Learn more here: https://nextjs.org/telemetry # Uncomment the following line in case you want to disable telemetry during the build. ENV NEXT_TELEMETRY_DISABLED 1 RUN npm run build # Download Bitwarden Secrets Manager CLI FROM base AS bws ARG BWS_VERSION=2.1.0 ARG BWS_ARCH=x86_64-unknown-linux-musl RUN apk add --no-cache curl unzip RUN curl -fsSL "https://github.com/bitwarden/sdk-sm/releases/download/bws-v${BWS_VERSION}/bws-${BWS_ARCH}-${BWS_VERSION}.zip" -o /tmp/bws.zip && \ mkdir -p /tmp/bws-extract && \ unzip -q /tmp/bws.zip -d /tmp/bws-extract && \ find /tmp/bws-extract -type f -name bws -exec chmod +x {} \; -exec cp {} /usr/local/bin/bws \; && \ /usr/local/bin/bws --version # Production image, copy all the files and run next FROM base AS runner WORKDIR /app ENV NODE_ENV production ENV NEXT_TELEMETRY_DISABLED 1 RUN addgroup --system --gid 1001 nodejs RUN adduser --system --uid 1001 nextjs COPY --from=builder /app/public ./public # Set the correct permission for prerender cache RUN mkdir .next RUN chown nextjs:nodejs .next # Automatically leverage output traces to reduce image size # https://nextjs.org/docs/advanced-features/output-file-tracing COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./ COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static # Copy Bitwarden Secrets Manager CLI and entrypoint COPY --from=bws /usr/local/bin/bws /usr/local/bin/bws COPY docker-entrypoint.sh /app/docker-entrypoint.sh RUN chmod +x /app/docker-entrypoint.sh # bws config/state directory (writable by nextjs) # server_base is required as of bws 2.x — the profile errors with # "Profile has no `server_base` or `server_identity`" without it, even # for the default Bitwarden cloud instance. RUN mkdir -p /app/.config/bws && chown -R nextjs:nodejs /app/.config/bws && \ printf '[profiles.default]\nserver_base = "https://vault.bitwarden.com"\nstate_dir = "/app/.config/bws/state"\n' > /app/.config/bws/config && \ chown nextjs:nodejs /app/.config/bws/config ENV BWS_CONFIG_FILE=/app/.config/bws/config USER nextjs # Use custom port 3100 instead of 3000 EXPOSE 3100 ENV PORT 3100 ENV HOSTNAME "0.0.0.0" CMD ["/app/docker-entrypoint.sh"]