Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 18 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -276,7 +276,8 @@ jobs:
file: ${{ matrix.file }}
target: ${{ matrix.target }}
push: false
load: false
load: ${{ matrix.service == 'bot' }}
tags: lucky-${{ matrix.service }}:ci
provenance: false
sbom: false
cache-from: type=gha,scope=${{ matrix.service }}
Expand All @@ -292,14 +293,29 @@ jobs:
file: ${{ matrix.file }}
target: ${{ matrix.target }}
push: false
load: false
load: ${{ matrix.service == 'bot' }}
tags: lucky-${{ matrix.service }}:ci
provenance: false
sbom: false
cache-from: type=gha,scope=${{ matrix.service }}
cache-to: type=gha,mode=max,scope=${{ matrix.service }}
build-args: |
COMMIT_SHA=${{ github.sha }}
NPM_CACHE_KEY=${{ hashFiles('package-lock.json') }}
# A built image is not a working image: the bot's native addons
# (@discordjs/opus) and the baked Prisma engines only fail at
# require()-time, which `docker build` never reaches. #1735 shipped a
# Prisma engine that crash-looped 262x behind a green build. Load the
# real production-bot image and require the modules for real.
- name: Verify native modules load — bot
if: matrix.service == 'bot'
run: |
docker run --rm lucky-bot:ci node -e "
const { OpusEncoder } = require('@discordjs/opus');
const frame = new OpusEncoder(48000, 2).encode(Buffer.alloc(3840));
if (!frame.length) throw new Error('opus encoded an empty frame');
console.log('opus OK — encoded', frame.length, 'bytes');
"

docker-build-check:
name: Build — Docker images
Expand Down
15 changes: 10 additions & 5 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@

# Build stage — installs all deps, generates prisma, builds shared + target
FROM node:${NODE_VERSION} AS build
ARG NPM_CACHE_KEY

Check warning on line 57 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — frontend

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 57 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — backend

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 57 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — bot

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

RUN apk add --no-cache git build-base python3 python3-dev opus-dev && rm -rf /var/cache/apk/* && npm install -g npm@latest && npm cache clean --force

Expand Down Expand Up @@ -98,7 +98,7 @@

# Production deps — slim install (no dev deps)
FROM node:${NODE_VERSION} AS deps-production
ARG NPM_CACHE_KEY

Check warning on line 101 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — backend

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 101 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — bot

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

# build-base + python3-dev + opus-dev: @discordjs/opus falls back to a source
# build whenever its musl prebuilt is missing for the current base image
Expand All @@ -115,11 +115,16 @@
COPY packages/backend/package*.json ./packages/backend/
COPY packages/frontend/package*.json ./packages/frontend/

RUN --mount=type=cache,id=npm-deps-production-v4-${NPM_CACHE_KEY},target=/root/.npm,sharing=locked \
YOUTUBE_DL_SKIP_DOWNLOAD=1 \
YOUTUBE_DL_SKIP_PYTHON_CHECK=1 \
npm ci --legacy-peer-deps --omit=dev --no-audit --no-fund && \
(npm cache verify 2>/dev/null || true)
# Reuse already-compiled node_modules from build stage (avoids double @discordjs/opus
# compilation). Copy root + workspace node_modules, then prune devDeps in-place while
# preserving the pre-built .node binary.
COPY --from=build /app/node_modules ./node_modules
COPY --from=build /app/packages/shared/node_modules ./packages/shared/node_modules
COPY --from=build /app/packages/bot/node_modules ./packages/bot/node_modules
COPY --from=build /app/packages/backend/node_modules ./packages/backend/node_modules
COPY --from=build /app/packages/frontend/node_modules ./packages/frontend/node_modules
Comment thread
LucasSantana-Dev marked this conversation as resolved.

RUN npm prune --omit=dev --legacy-peer-deps
Comment thread
LucasSantana-Dev marked this conversation as resolved.

# Production stage — bot (full runtime with ffmpeg/opus/yt-dlp)
FROM base-runtime AS production-bot
Expand Down
Loading