Skip to content

chore: pin Node 24 (24.21.0) across CI, Docker images, and Volta - #257

Merged
Deepesh-Katudia merged 1 commit into
mainfrom
chore/node-24-pin
Oct 1, 2026
Merged

Deepesh-Katudia merged 1 commit into
mainfrom
chore/node-24-pin

Conversation

@sweksha-cloud

@sweksha-cloud sweksha-cloud commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Pins Node.js to 24.21.0 everywhere. Before this, Node was 20.19.0 in CI and Volta, 18.20.8 in the react Dockerfile, and floating node:alpine in the three backend Dockerfiles, which currently resolves to Node 26, so backend images could change Node major on any rebuild with no code change.

Type of Change

  • New feature
  • Bug fix
  • Refactor
  • Documentation update
  • Style/UI update
  • Performance improvement
  • Other (please specify): toolchain / runtime version pin

Key Changes

  • .github/workflows/ci.yml: setup-node → 24.21.0
  • react-ystemandchess/Dockerfile: both stages → node:24.21.0-alpine
  • chessServer, stockfishServer, middlewareNode Dockerfiles: node:alpine → node:24.21.0-alpine
  • volta.node → 24.21.0 and "engines": { "node": ">=24 <25" } in the root and each service package.json. Volta resolves the nearest package.json, so pinning only the root would leave anyone running npm start inside a service directory on 20.19.0.
  • Lockfiles: only the matching engines entry (npm's unrelated dev-flag/name churn was dropped to keep the diff reviewable).
  • README.md: setup instructions updated from 18.20.8 to 24.21.0.

Testing

  • Unit tests added/updated
  • Integration tests added/updated
  • Manual testing performed
  • All tests pass

All on Node 24.21.0 after a clean npm ci:

  • middlewareNode 264/264, chessServer 33/33, stockfishServer 16/16, react-ystemandchess 155/155
  • react-ystemandchess production build compiles (existing lint/source-map warnings only, unrelated to Node)
  • CI on this PR: passing.
  • All four Docker images build on node:24.21.0-alpine and were booted:
    • react-ystemandchess: serves HTTP 200
    • chessServer: Socket.IO polling endpoint returns 200
    • middlewareNode (with a mongo:6 container): connects, seeds, GET / returns 200, and POST /auth/login as the student test user returns 200
    • stockfishServer: /health returns {"status":"ok"} and the Socket.IO endpoint returns 200. The engine binary itself does not run in this image (pre-existing on main, see the comment below)

Not tested

  • Playwright E2E (npx playwright test): needs the full stack running; CI doesn't run it either.
  • A real Stockfish engine session in the container: the binary fails to launch on Alpine regardless of Node version (see comment), so there was nothing Node-24-specific to verify there.
  • chessclient: not changed by this PR (its Dockerfile still uses node:18-alpine as the build stage and is slated to become plain nginx).

Merge notes

  • Trial-merged into sahana/208-azure-cicd: the only conflict is the expected duplicate Test middlewareNode step in ci.yml (keep Sahana's). No other files conflict.
  • See the comment below about the Stockfish engine binary in the stockfishServer image. It's pre-existing on main and deliberately not changed here.

🤖 Generated with Claude Code

Node was 20.19.0 in CI and Volta, 18.20.8 in the react Dockerfile, and
floating `node:alpine` (currently Node 26) in the three backend
Dockerfiles, so backend images changed Node major on rebuild with no
code change.

- ci.yml: setup-node 24.21.0
- react-ystemandchess/Dockerfile: both stages node:24.21.0-alpine
- chessServer, stockfishServer, middlewareNode Dockerfiles:
  node:24.21.0-alpine
- volta.node 24.21.0 and engines.node ">=24 <25" in the root and each
  service package.json (Volta resolves the nearest package.json, so
  pinning only the root would leave service dirs on 20.19.0)
- lockfiles: only the matching engines entry
- README: Node 24.21.0 setup instructions

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sweksha-cloud

Copy link
Copy Markdown
Collaborator Author

Heads-up for the stockfishServer "extra look": the Stockfish engine can't start in the Docker image (pre-existing, not caused by this PR)

StockfishManager spawns src/bin/stockfish_11_linux, which is a glibc x86-64 binary:

ELF 64-bit LSB pie executable, x86-64, dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0

Alpine images use musl and don't ship /lib64/ld-linux-x86-64.so.2, so the engine fails to launch inside the image. Tested with --platform linux/amd64, piping uci / go depth 10 into the binary:

Image Result
main (node:alpine, currently Node 26.10.0) ❌ fails: /lib64/ld-linux-x86-64.so.2 not found
this PR (node:24.21.0-alpine) ❌ same failure
node:24.21.0-slim (Debian, glibc) ✅ uciok … bestmove

So it's broken on main today, independent of the Node version. It's easy to miss because POST /api/analyze silently falls back to a material-count heuristic when no engine is available, and /health doesn't touch the engine, so HTTP checks still pass.

Possible fix (not included here, to keep this PR a pure version pin): switch stockfishServer/Dockerfile to FROM node:24.21.0-slim (one line; the binary ran fine there). Alternatives: install gcompat on Alpine, or ship a musl/static Stockfish build. Leaving the call to whoever owns the post-GHCR validation. Happy to open a follow-up PR for the -slim switch.

@sweksha-cloud

Copy link
Copy Markdown
Collaborator Author

Update: booted the middlewareNode and stockfishServer images too (details in the Testing section). All four images now boot on Node 24.21.0.

One non-Node finding while doing that: middleware can exit on a cold start if Mongo isn't accepting connections yet (1s dev timeout → falls back to mongodb-memory-server, which isn't in the production image). It happens on any Node version; written up on #256 since it affects the root docker-compose.yml.

@Deepesh-Katudia Deepesh-Katudia left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. This is a clean, well-scoped pin. 24.21.0 is the current latest Node 24 release, CI is green on it, and replacing the floating node:alpine tag (which currently resolves to Node 26) in the three backend images is the important fix here. Thanks for booting all four images and for writing up the Stockfish finding.

Non-blocking comments:

Medium

  1. Exact-patch Docker pins won't pick up security updates. node:24.21.0-alpine is frozen, so every Node 24 security release now means a manual bump in about 12 places (5 FROM lines, CI, Volta, README). Suggest a follow-up adding a Dependabot docker + npm config (or Renovate) so these come in as PRs. The other option is node:24-alpine if we'd rather take patches automatically than have exact reproducibility.
  2. The Stockfish engine can't run in the stockfishServer image. This is pre-existing and not caused by this PR, as your comment explains. Since /api/analyze silently falls back to the material-count heuristic, production analysis is degraded without anyone noticing. Please open the -slim follow-up PR you offered (or an issue) so it's tracked.

Low
3. ci.yml could use node-version-file: package.json. setup-node@v4 reads volta.node, which would make the root package.json the single source of truth instead of repeating the version.
4. engines only produces warnings unless engine-strict=true is set in .npmrc. That's probably what we want for contributors; just noting that it isn't enforced.
5. chessclient/Dockerfile is still on node:18-alpine (Node 18 is EOL). It's out of scope here, but worth an issue so it isn't forgotten.

Merge note: chore/frontend-cra-to-vite touches the same files: ci.yml, react-ystemandchess/Dockerfile, and the frontend package.json and lockfile. Expect small conflicts in whichever lands second. Node 24 is compatible with Vite, which needs at least 20.19.

@Deepesh-Katudia
Deepesh-Katudia merged commit eadb73f into main Oct 1, 2026
1 check passed
sweksha-cloud added a commit that referenced this pull request Oct 2, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants