Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 15 additions & 6 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@
# build-backend, build-frontend), split apart to avoid coupling unrelated
# COPY --from steps to each other's build RUNs — see the comments there.
FROM node:${NODE_VERSION} AS build
ARG NPM_CACHE_KEY

Check warning on line 66 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — frontend

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 66 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — backend

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 66 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — bot

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

RUN apk add --no-cache git build-base python3 python3-dev opus-dev && rm -rf /var/cache/apk/* && npm install -g npm@latest && npm cache clean --force

Expand Down Expand Up @@ -156,7 +156,7 @@
# and without the GHA cache, alone and concurrent, disk headroom confirmed
# fine every time — never root-caused beyond "eliminate the unneeded COPY").
FROM node:${NODE_VERSION} AS deps-production-base
ARG NPM_CACHE_KEY

Check warning on line 159 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — backend

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 159 in Dockerfile

View workflow job for this annotation

GitHub Actions / Build — bot

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NPM_CACHE_KEY") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

# build-base + python3-dev + opus-dev: @discordjs/opus falls back to a source
# build whenever its musl prebuilt is missing for the current base image
Expand All @@ -177,17 +177,26 @@
COPY packages/backend/package*.json ./packages/backend/
COPY packages/frontend/package*.json ./packages/frontend/

# Reuse already-compiled node_modules from the pre-build checkpoint (avoids
# double @discordjs/opus compilation).
COPY --from=installed-deps /app/node_modules ./node_modules
COPY --from=installed-deps /app/packages/shared/node_modules ./packages/shared/node_modules
# Independent npm ci instead of COPY --from=installed-deps (issue #2015).
# installed-deps is concurrently extended by a second live branch
# (source-copied, via FROM inheritance) for the whole rest of this build —
# COPY --from of it while that's happening hit a BuildKit race ("failed to
# calculate checksum of ref ...: not found"), non-deterministically but at
# a very high rate on GH Actions runners, and never resolved by cache
# tuning or retries alone (#2002, #2013, #2016). Running npm ci here
# duplicates the @discordjs/opus native compile once — this stage is
# shared by both deps-production-bot and deps-production-backend below, so
# it's a one-time cost per build, not per target — but fully decouples this
# lineage from installed-deps: no more cross-stage read of a stage still
# being written to elsewhere.
RUN --mount=type=cache,id=npm-build-stage-v4-${NPM_CACHE_KEY},target=/root/.npm,sharing=locked \
YOUTUBE_DL_SKIP_DOWNLOAD=1 \
npm ci --legacy-peer-deps --no-audit --no-fund

FROM deps-production-base AS deps-production-bot
COPY --from=installed-deps /app/packages/bot/node_modules ./packages/bot/node_modules
RUN npm prune --omit=dev --legacy-peer-deps

FROM deps-production-base AS deps-production-backend
COPY --from=installed-deps /app/packages/backend/node_modules ./packages/backend/node_modules
RUN npm prune --omit=dev --legacy-peer-deps

# Production stage — bot (full runtime with ffmpeg/opus/yt-dlp)
Expand Down
Loading