From 3bb4d5aa656b5dcf1352a6f35225cbbde4b8d0c9 Mon Sep 17 00:00:00 2001 From: amania-jailbreak Date: Wed, 5 Aug 2026 13:16:39 +0900 Subject: [PATCH] =?UTF-8?q?docker:=20Coolify=E5=AF=BE=E5=BF=9C=E3=81=AE?= =?UTF-8?q?=E3=81=9F=E3=82=81Dockerfile=E3=83=93=E3=83=AB=E3=83=89?= =?UTF-8?q?=E3=81=AB=E7=A7=BB=E8=A1=8C=E3=81=97bind=20mount=E4=BE=9D?= =?UTF-8?q?=E5=AD=98=E3=82=92=E6=8E=92=E9=99=A4?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - ルートDockerfileで npm ci をビルド時に一元実行(node_modulesの競合破損を防止) - web/api/workerをYAMLアンカーで共通ビルド構成に変更し、.:/workspace のbind mountを削除 - vinextは --hostname でバインド指定(--host は無視される) - minio-initを削除(APIがbucketを自動作成)し、MinIOをexposeのみの内部公開に変更 - .dockerignore を追加し、.wranglerディレクトリをDockerfile内で事前作成 --- .dockerignore | 24 +++++++++++++ .env.example | 6 +++- Dockerfile | 16 +++++++++ docker-compose.yml | 90 ++++++++++++++++++++-------------------------- 4 files changed, 83 insertions(+), 53 deletions(-) create mode 100644 .dockerignore create mode 100644 Dockerfile diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..18deda5 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,24 @@ +# dependencies +node_modules + +# build outputs / caches +.next +dist +coverage +.vinext +.wrangler + +# local data / misc +.data +.DS_Store + +# secrets & env files +.env +.env.* + +# logs +npm-debug.log* + +# git / tooling +.git +.vercel diff --git a/.env.example b/.env.example index ae2d283..492bb8a 100644 --- a/.env.example +++ b/.env.example @@ -6,6 +6,10 @@ NEXT_PUBLIC_AUTH_MODE=demo # --- Storage (MinIO via docker compose) ------------------------------------- # Leave DATABASE_URL empty to run with an in-memory store instead of Postgres. +# docker-compose.yml keeps MinIO internal-only (no published ports/domain) and +# all uploads flow through the API, so the API uses the internal endpoint. +# When running the API on the host instead of inside compose, re-add MinIO's +# host ports (9000/9001) to docker-compose.yml first. DATABASE_URL=postgres://altdock:altdock@localhost:5432/altdock STORAGE_MODE=s3 S3_ENDPOINT=http://localhost:9000 @@ -17,7 +21,7 @@ S3_FORCE_PATH_STYLE=true # MinIO root credentials, consumed by docker-compose.yml. CHANGE in production. MINIO_ROOT_USER=minioadmin MINIO_ROOT_PASSWORD=minioadmin123 -# Only needed when MinIO is behind a reverse proxy / domain (e.g. on Coolify): +# Only needed when MinIO is exposed behind a reverse proxy / domain: MINIO_SERVER_URL= MINIO_BROWSER_REDIRECT_URL= diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..cada23e --- /dev/null +++ b/Dockerfile @@ -0,0 +1,16 @@ +FROM node:22-bookworm + +WORKDIR /workspace + +# package-lock.json is committed, so npm ci installs the exact dependency tree. +COPY package.json package-lock.json ./ + +RUN npm ci --no-audit --no-fund + +COPY . . + +# vinext/wrangler writes logs and registry state under .wrangler; the directory +# itself is git/dockerignored, so create it explicitly. +RUN mkdir -p /workspace/.wrangler + +CMD ["npm", "run", "dev"] diff --git a/docker-compose.yml b/docker-compose.yml index 3f9a082..dd207d6 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -3,14 +3,24 @@ # Environment Variables / secrets panel. # # Coolify notes: -# - All credentials are parameterized; set them in Coolify's env to avoid -# the insecure local defaults. -# - MinIO has a real healthcheck, so api/worker wait until it can serve. -# - The API also creates the S3 bucket itself on startup (ensureBucket), -# so the stack no longer depends on minio-init completing successfully. -# - If you expose MinIO through a domain, set MINIO_SERVER_URL (public S3 API -# origin) and MINIO_BROWSER_REDIRECT_URL (public console origin) so -# presigned upload URLs and console redirects work from the browser. +# - web/api/worker are all built from the same root Dockerfile and run from +# the image contents. There are no bind mounts, so nothing depends on +# Coolify mounting the git repository at /workspace (relative paths are +# mounted as empty named volumes there). +# - node_modules is baked into the image once by `npm ci` at build time, so +# the containers never race each other running npm install. +# - MinIO is fully private: uploads always flow through the API (browser -> +# API -> MinIO) and the API creates its bucket on startup, so no +# minio-init container and no published MinIO ports/domain are required. +# - postgres published port exists only for local development; on Coolify, +# public traffic goes through its reverse proxy and MinIO stays internal. + +x-altdock-app: &altdock-app + build: + context: . + dockerfile: Dockerfile + working_dir: /workspace + restart: unless-stopped services: postgres: @@ -35,12 +45,11 @@ services: environment: MINIO_ROOT_USER: ${MINIO_ROOT_USER:-minioadmin} MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-minioadmin123} - # Public origins, only needed when MinIO is behind a reverse proxy/domain. - MINIO_SERVER_URL: ${MINIO_SERVER_URL:-} - MINIO_BROWSER_REDIRECT_URL: ${MINIO_BROWSER_REDIRECT_URL:-} - ports: - - "9000:9000" - - "9001:9001" + # Internal-only: the API reaches MinIO over the compose network and uploads + # are proxied through the API, so no host ports / public domain are needed. + expose: + - "9000" + - "9001" volumes: - minio-data:/data healthcheck: @@ -50,35 +59,16 @@ services: retries: 12 start_period: 10s - # Optional belt-and-suspenders: pre-creates the bucket. The API does the - # same on startup, so this can be removed without affecting functionality. - minio-init: - image: minio/mc:latest - depends_on: - minio: - condition: service_healthy - entrypoint: ["/bin/sh", "-c"] - command: >- - "until mc alias set local http://minio:9000 ${MINIO_ROOT_USER:-minioadmin} ${MINIO_ROOT_PASSWORD:-minioadmin123}; do sleep 1; done; - mc mb --ignore-existing local/${S3_BUCKET:-altdock}" - environment: - MINIO_ROOT_USER: ${MINIO_ROOT_USER:-minioadmin} - MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-minioadmin123} - api: - image: node:22-bookworm - working_dir: /workspace - command: sh -c "npm install --no-audit --no-fund && npm run dev:api" + <<: *altdock-app + command: sh -c "npm run db:migrate && exec npm run dev:api" environment: - NODE_ENV: development PORT: 4000 - PUBLIC_BASE_URL: ${PUBLIC_BASE_URL:-http://localhost:4000} - WEB_ORIGIN: ${WEB_ORIGIN:-http://localhost:3000} DATABASE_URL: postgres://${POSTGRES_USER:-altdock}:${POSTGRES_PASSWORD:-altdock}@postgres:5432/${POSTGRES_DB:-altdock} STORAGE_MODE: s3 - # S3_ENDPOINT is the internal address; presigned URLs resolve via the - # public MINIO_SERVER_URL when set. - S3_ENDPOINT: ${S3_ENDPOINT:-http://minio:9000} + # Internal address only; uploads are proxied through the API, so MinIO + # never needs a public URL. + S3_ENDPOINT: http://minio:9000 S3_REGION: ${S3_REGION:-us-east-1} S3_BUCKET: ${S3_BUCKET:-altdock} S3_ACCESS_KEY_ID: ${MINIO_ROOT_USER:-minioadmin} @@ -86,10 +76,10 @@ services: S3_FORCE_PATH_STYLE: "true" AUTH_MODE: ${AUTH_MODE:-demo} PROCESS_INLINE: "false" + PUBLIC_BASE_URL: ${PUBLIC_BASE_URL:-http://localhost:4000} + WEB_ORIGIN: ${WEB_ORIGIN:-http://localhost:3000} ports: - "4000:4000" - volumes: - - .:/workspace depends_on: postgres: condition: service_healthy @@ -97,14 +87,12 @@ services: condition: service_healthy worker: - image: node:22-bookworm - working_dir: /workspace - command: sh -c "npm install --no-audit --no-fund && npm run dev:worker" + <<: *altdock-app + command: npm run dev:worker environment: - NODE_ENV: development DATABASE_URL: postgres://${POSTGRES_USER:-altdock}:${POSTGRES_PASSWORD:-altdock}@postgres:5432/${POSTGRES_DB:-altdock} STORAGE_MODE: s3 - S3_ENDPOINT: ${S3_ENDPOINT:-http://minio:9000} + S3_ENDPOINT: http://minio:9000 S3_REGION: ${S3_REGION:-us-east-1} S3_BUCKET: ${S3_BUCKET:-altdock} S3_ACCESS_KEY_ID: ${MINIO_ROOT_USER:-minioadmin} @@ -112,8 +100,6 @@ services: S3_FORCE_PATH_STYLE: "true" AUTH_MODE: ${AUTH_MODE:-demo} PROCESS_INLINE: "false" - volumes: - - .:/workspace depends_on: postgres: condition: service_healthy @@ -121,15 +107,15 @@ services: condition: service_healthy web: - image: node:22-bookworm - working_dir: /workspace - command: sh -c "npm install --no-audit --no-fund && npm run dev -- --host 0.0.0.0" + <<: *altdock-app + # vinext uses --hostname (not vite's --host) to bind the dev server. + command: npm run dev -- --hostname 0.0.0.0 environment: + HOST: 0.0.0.0 NEXT_PUBLIC_API_BASE_URL: ${NEXT_PUBLIC_API_BASE_URL:-http://localhost:4000} + NEXT_PUBLIC_AUTH_MODE: ${AUTH_MODE:-demo} ports: - "3000:3000" - volumes: - - .:/workspace depends_on: api: condition: service_started