Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ env:
jobs:
build-and-push:
runs-on: ubuntu-latest
timeout-minutes: 60
permissions:
contents: read
# Required for pushing to GHCR with the automatic GITHUB_TOKEN, so no PAT has to be
Expand Down Expand Up @@ -87,6 +88,7 @@ jobs:
# instead and `latest` keeps pointing at the last real release.

- name: Build and push
timeout-minutes: 55
uses: docker/build-push-action@v6
with:
context: .
Expand Down Expand Up @@ -115,6 +117,7 @@ jobs:
# execute the arm64 image without paying emulation for a whole boot.
- name: Smoke-test the published image
if: github.event_name != 'pull_request'
timeout-minutes: 5
run: |
set -euo pipefail
IMAGE=$(echo "${{ steps.meta.outputs.tags }}" | head -n1)
Expand Down
39 changes: 37 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
# than something the operator has to remember: an image cannot go out with a stale bundle.

# ---------- stage 1: the console ----------
FROM node:22-alpine AS frontend
FROM --platform=$BUILDPLATFORM node:22-alpine AS frontend

# Optional mirrors, for building on a network that cannot reach the public registries.
# Empty by default, so an unset build arg means "use registry.npmjs.org / pypi.org" and CI
Expand All @@ -21,7 +21,42 @@ WORKDIR /build
# change, not on every source edit. `npm ci` (not `install`) installs the exact
# package-lock.json tree, so an image built today and one built next month are identical.
COPY frontend/package.json frontend/package-lock.json ./
RUN npm ci ${NPM_REGISTRY:+--registry "$NPM_REGISTRY"}
RUN set -eu; \
logs_dir="${HOME:-/root}/.npm/_logs"; \
status=0; \
npm ci \
--no-audit \
--foreground-scripts \
--loglevel=info \
--replace-registry-host=always \
--timing \
--fetch-timeout=120000 \
--fetch-retries=2 \
--fetch-retry-factor=2 \
--fetch-retry-mintimeout=10000 \
--fetch-retry-maxtimeout=60000 \
${NPM_REGISTRY:+--registry "$NPM_REGISTRY"} \
|| status=$?; \
if [ "$status" -ne 0 ]; then \
echo "npm ci failed; showing sanitized npm logs"; \
found=0; \
for log in "$logs_dir"/*.log; do \
[ -f "$log" ] || continue; \
found=1; \
echo "----- $(basename "$log") -----"; \
sed -E \
-e 's#(//)[^/@[:space:]]+:[^/@[:space:]]+@#\1***:***@#g' \
-e 's#([?&]_authToken=)[^&[:space:]]+#\1***#g' \
-e 's#(//[^[:space:]]+/:_authToken=)[^[:space:]]+#\1***#g' \
-e 's#(Authorization: (Bearer|Basic) )[[:graph:]]+#\1***#g' \
-e 's#(npm_[A-Za-z0-9_-]*=)[^[:space:]]+#\1***#g' \
"$log"; \
done; \
if [ "$found" -eq 0 ]; then \
echo "No npm logs found under $logs_dir"; \
fi; \
exit "$status"; \
fi

COPY frontend/ ./
RUN npm run build
Expand Down
Loading
Loading