d38f953dfc
wget resolves 'localhost' to IPv6 [::1] but nginx only listens on IPv4 0.0.0.0:80, causing connection refused. Using 127.0.0.1 ensures IPv4 connection and healthy container status.
47 lines
1.0 KiB
Docker
47 lines
1.0 KiB
Docker
# Build stage
|
|
FROM node:20-alpine as builder
|
|
|
|
WORKDIR /build
|
|
|
|
# Copy package files
|
|
COPY package.json package-lock.json* ./
|
|
|
|
# Install dependencies
|
|
RUN npm install
|
|
|
|
# Copy source code
|
|
COPY . .
|
|
|
|
# Build production bundle
|
|
RUN npm run build
|
|
|
|
# Production stage
|
|
FROM nginx:alpine
|
|
|
|
# Create non-root user
|
|
RUN addgroup -g 1001 -S nodejs && adduser -S nextjs -u 1001
|
|
|
|
# Copy custom nginx config
|
|
COPY nginx.conf /etc/nginx/conf.d/default.conf
|
|
|
|
# Copy built assets from builder
|
|
COPY --from=builder --chown=nextjs:nodejs /build/dist /usr/share/nginx/html
|
|
|
|
# Create required directories and fix permissions for non-root user
|
|
RUN mkdir -p /var/cache/nginx /var/run /run && \
|
|
chown -R nextjs:nodejs /var/cache/nginx /var/run /run /usr/share/nginx/html && \
|
|
chmod 755 /run /var/run
|
|
|
|
# Switch to non-root user
|
|
USER nextjs
|
|
|
|
# Expose port
|
|
EXPOSE 80
|
|
|
|
# Health check
|
|
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
|
|
CMD wget --quiet --tries=1 --spider http://127.0.0.1/ || exit 1
|
|
|
|
# Start nginx
|
|
CMD ["nginx", "-g", "daemon off;"]
|