Files
dtf-system/deploy/Dockerfile.web
Cauê Faleiros 536510b148
All checks were successful
Build and deploy / Validate source (push) Successful in 7s
Build and deploy / Integration suite on a real stack (push) Successful in 2m9s
Build and deploy / Secret scan and release gate (push) Successful in 6s
Build and deploy / Publish images (push) Successful in 1m44s
fix: version the Site's scripts by content so a release never meets a cached old one
The proxy in front of production caches .js and .css for hours. After the
last release the Site got the new index.html with the old site-flow.js,
which wrote to an element the new page no longer has; the error left
"Adicionar ao carrinho" disabled. The web build now addresses every local
script and stylesheet by a hash of its content, replacing the hand-kept
?v= markers, so a new release always loads its own files.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 11:27:55 -03:00

35 lines
1.7 KiB
Docker

# syntax=docker/dockerfile:1
ARG PYTHON_BASE_IMAGE=python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9
# Both bases are pinned by digest; override with the repository variables to
# move them forward deliberately.
# nginx 1.31.6. The 1.28 line pins nginx=1.28.3-r1 in /etc/apk/world, so its five
# HIGH findings cannot be upgraded in place; 1.29 scans worse. This one is clean.
ARG NGINX_BASE_IMAGE=nginx:alpine@sha256:62ff2089abf5a9ed33bd232895bef5e22f7bb4b200675cec49a5ebc48e3d4ac8
FROM ${PYTHON_BASE_IMAGE} AS policy
WORKDIR /build
COPY web /build/web
COPY infra /build/infra
COPY deploy /build/deploy
ENV NGINX_TEMPLATE=/build/deploy/nginx.conf.template
RUN python infra/compile_web.py
FROM ${NGINX_BASE_IMAGE}
# Same reason as the API image: a pinned base freezes its packages.
RUN apk upgrade --no-cache
ARG VCS_REF=unknown
LABEL org.opencontainers.image.title="DTF Site and Kanban" \
org.opencontainers.image.revision="$VCS_REF" \
org.opencontainers.image.source="DTF System repository"
ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https://invalid.example
COPY --from=policy /build/default.conf.template /etc/nginx/templates/default.conf.template
# The HTML from the policy stage, with every asset address versioned.
COPY --from=policy /build/web/ /usr/share/nginx/html/
# The official entrypoint renders the server configuration at startup and Nginx
# writes its PID/cache files. Keep the service non-root while granting it
# ownership of only those runtime locations. This works in Docker Swarm,
# where the previous read-only/tmpfs combination was not mounted as expected.
RUN chown -R 101:101 /etc/nginx/conf.d /var/cache/nginx /run
USER 101:101
EXPOSE 8080