-
Notifications
You must be signed in to change notification settings - Fork 15
Expand file tree
/
Copy pathDockerfile
More file actions
69 lines (65 loc) · 2.9 KB
/
Copy pathDockerfile
File metadata and controls
69 lines (65 loc) · 2.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
# syntax=docker/dockerfile:1
# CI/release callers pass Bun's Socket Firewall config as a BuildKit secret and
# set SFW_REQUIRED=true. Local Docker builds omit both and keep using Bun's
# normal public-registry configuration.
ARG SFW_REQUIRED=false
# Build stage: compile TypeScript to dist/ from the bun lockfile.
# bun.lock pins tree-sitter-kotlin (a transitive devDep via @workos/openapi-spec
# -> @workos/oagen) to a git+ssh URL that can't clone inside the image without
# SSH credentials. Rewrite that one entry to the `github:` shorthand so bun
# downloads a tarball over HTTPS at the same pinned commit, and blank its
# integrity hash (the hash was computed from a git clone, not a tarball). Every
# other dependency — including typescript@5.9.3 — stays at its locked version,
# keeping the build reproducible.
FROM oven/bun:1.4.2 AS builder
ARG SFW_REQUIRED
WORKDIR /app
COPY package.json bun.lock ./
RUN --mount=type=secret,id=sfw_bunfig,target=/run/secrets/.bunfig.toml \
set -eu; \
if [ "${SFW_REQUIRED:-false}" = "true" ] && [ ! -s /run/secrets/.bunfig.toml ]; then \
echo "Socket Firewall Bun config secret is required for Docker dependency installs." >&2; \
exit 1; \
fi; \
if [ -s /run/secrets/.bunfig.toml ]; then \
export XDG_CONFIG_HOME=/run/secrets; \
fi; \
sed -i \
-e 's|git+ssh://git@github.com/fwcd/tree-sitter-kotlin.git#|github:fwcd/tree-sitter-kotlin#|g' \
-e 's/"sha512-onbog[^"]*"/""/g' \
bun.lock \
&& bun install --frozen-lockfile --ignore-scripts
COPY tsconfig.json ./
COPY src/ ./src/
RUN bun run build
# Deps stage: install production dependencies from the frozen bun lockfile.
# This stage only needs production deps (no git+ssh transitive devDeps), so
# the bun lockfile works correctly.
FROM oven/bun:1.4.2 AS deps
ARG SFW_REQUIRED
WORKDIR /app
COPY package.json bun.lock ./
RUN --mount=type=secret,id=sfw_bunfig,target=/run/secrets/.bunfig.toml \
set -eu; \
if [ "${SFW_REQUIRED:-false}" = "true" ] && [ ! -s /run/secrets/.bunfig.toml ]; then \
echo "Socket Firewall Bun config secret is required for Docker dependency installs." >&2; \
exit 1; \
fi; \
if [ -s /run/secrets/.bunfig.toml ]; then \
export XDG_CONFIG_HOME=/run/secrets; \
fi; \
bun install --frozen-lockfile --production --ignore-scripts
# Runtime stage: minimal Node image with only what the emulator needs.
FROM node:22-alpine
LABEL org.opencontainers.image.source="https://github.com/workos/emulate"
LABEL org.opencontainers.image.title="WorkOS Emulate"
LABEL org.opencontainers.image.description="Local WorkOS API emulator for tests and development"
WORKDIR /app
RUN addgroup --system --gid 1001 nodejs && adduser --system --uid 1001 --ingroup nodejs emulate
COPY --from=deps /app/node_modules ./node_modules
COPY --from=builder /app/dist ./dist
COPY package.json ./
USER emulate
EXPOSE 4100
ENTRYPOINT ["node", "dist/cli.js"]
CMD ["--host", "0.0.0.0"]