diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..bd7248b --- /dev/null +++ b/.dockerignore @@ -0,0 +1,7 @@ +.git +node_modules +**/node_modules +**/dist +# proxy.Dockerfile copies this single host-built file (see its header comment); everything else +# under dist/ stays out of the build context so the turn image's `pnpm install` starts clean. +!packages/daemon/dist/proxy.js diff --git a/docker/Dockerfile b/docker/Dockerfile index 2499d1c..b2c187f 100644 --- a/docker/Dockerfile +++ b/docker/Dockerfile @@ -28,6 +28,10 @@ # etc. all resolve under $HOME=/home/radial). FROM node:24-slim AS build +# CI=true: pnpm must never prompt (no TTY in a docker build); COREPACK_ENABLE_DOWNLOAD_PROMPT +# likewise silences corepack's download confirmation. The root .dockerignore keeps the host's +# node_modules/dist out of the build context so `pnpm install` starts from a clean slate. +ENV CI=true COREPACK_ENABLE_DOWNLOAD_PROMPT=0 RUN corepack enable WORKDIR /repo COPY . . @@ -60,8 +64,9 @@ RUN printf '#!/bin/sh\nexec node /opt/radial/sidecar/dist/cli.js "$@"\n' > /usr/ && chmod 0755 /usr/local/bin/radial # Non-root uid/gid 1000, matching ContainerSpec's default `--user 1000:1000` (container.ts). -RUN groupadd -g 1000 radial \ - && useradd -m -u 1000 -g 1000 -d /home/radial -s /usr/sbin/nologin radial +# node:24-slim already ships uid/gid 1000 (the `node` user); the runtime only needs the uid and a +# home directory at /home/radial ($HOME below) — the username is never referenced. +RUN mkdir -p /home/radial && chown 1000:1000 /home/radial USER 1000:1000 ENV HOME=/home/radial diff --git a/docker/proxy.Dockerfile b/docker/proxy.Dockerfile index 462fc05..238a7da 100644 --- a/docker/proxy.Dockerfile +++ b/docker/proxy.Dockerfile @@ -15,8 +15,7 @@ FROM node:24-slim AS runtime # Non-root uid/gid 1000, matching this repo's sandbox convention for every container it runs. -RUN groupadd -g 1000 radial \ - && useradd -m -u 1000 -g 1000 -d /home/radial -s /usr/sbin/nologin radial +# node:24-slim already ships uid/gid 1000 (the `node` user); only the uid matters at runtime. COPY packages/daemon/dist/proxy.js /opt/radial/proxy.js RUN chmod 0644 /opt/radial/proxy.js diff --git a/package.json b/package.json index 542648c..4141ea9 100644 --- a/package.json +++ b/package.json @@ -3,6 +3,7 @@ "version": "0.0.0", "private": true, "type": "module", + "packageManager": "pnpm@10.28.2", "scripts": { "build": "pnpm -r build", "codegen": "pnpm --filter @radial/lexicons codegen",