Repository navigation
perf(docker): kill the cold-start chown bottleneck + warn about first-build time - #82
Merged
Merged
Conversation
…-build time Cold `docker compose up -d --build` spent ~7 of ~9.7 min in three recursive `chown -R` steps that rewrite every inode over huge node_modules / Chromium trees (api 169.9s, workers 128.7s Chromium-layer export, web 123.6s). Root cause: files were COPYed as root then chowned to node in a separate RUN layer. The runtime never actually writes under /app (uploads to object storage, web sessions are sealed iron-session cookies, not Astro's fs session store), so the whole-tree chown was unnecessary. - api / collab / web: COPY --chown=node:node the app code + build output; drop `RUN chown -R node:node /app`. Prod node_modules stays root-owned and world-readable (read-only at runtime). - workers: drop `chown -R node:node /app /ms-playwright` - the browsers path is already world-readable/executable via the existing `chmod -R a+rX`, and Chromium's writable profile lives under HOME=/home/node. Stops rewriting the entire Chromium tree into a second image layer. - All four images still run as the non-root `node` user (unchanged). Base images, versions, and tsc/build config untouched. Also: self-host-init.sh now warns that the first build takes several minutes and looks idle while images build (not a hang), and points at `docker compose logs -f`. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Signed-off-by: nbkdoesntknowcoding <nischaybk@theboringpeople.in>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the two issues from the Mnema cold-start benchmark: the ~7-min chown build bottleneck and the silent-wait UX gap.
The bottleneck
A cold
docker compose up -d --buildtook ~9:43; ~7 min was three recursivechown -Rsteps rewriting every inode over huge node_modules / Chromium trees (api 169.9s, workers 128.7s Chromium-layer export, web 123.6s).Root cause: files were COPYed as root then chowned to
nodein a separate RUN layer. But the runtime never writes under/app(uploads to object storage; web sessions are sealed iron-session cookies, not Astro's filesystem session store), so the whole-tree chown was unnecessary.Fix
COPY --chown=node:nodethe app code + build output; deleteRUN chown -R node:node /app. Prodnode_modulesstays root-owned + world-readable (read-only at runtime).chown -R node:node /app /ms-playwright— the browsers path is already world-readable/executable via the existingchmod -R a+rX, and Chromium's writable profile lives underHOME=/home/node. Stops rewriting the whole Chromium tree into a second layer.node. Base images, versions, tsc/build config untouched.Silent-wait UX
scripts/self-host-init.shnow warns the first build takes several minutes and looks idle while images build (not a hang), and points atdocker compose logs -f.Checklist