From 13bf83bb212ab21b67dabf6dfac4d11722dff148 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:03:25 -0800 Subject: [PATCH 1/9] feat: docker --- .dockerignore | 30 +++++++++++++++ .github/workflows/docker.yml | 73 ++++++++++++++++++++++++++++++++++++ Dockerfile | 67 +++++++++++++++++++++++++++++++++ docker-compose.example.yml | 58 ++++++++++++++++++++++++++++ 4 files changed, 228 insertions(+) create mode 100644 .dockerignore create mode 100644 .github/workflows/docker.yml create mode 100644 Dockerfile create mode 100644 docker-compose.example.yml diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..30c509f --- /dev/null +++ b/.dockerignore @@ -0,0 +1,30 @@ +node_modules +npm-debug.log* +yarn-debug.log* +pnpm-debug.log* +.env* +.git +.github +.vscode +.idea +*.swp +*~ +dist +build +web/dist +logs +*.log +.DS_Store +Thumbs.db +README.md +*.md +docs +.eslintrc.* +.prettierrc* +.prettierignore +tsconfig.json +eslint.config.mjs +Dockerfile* +docker-compose*.yml +.dockerignore +k8s diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml new file mode 100644 index 0000000..ae53b64 --- /dev/null +++ b/.github/workflows/docker.yml @@ -0,0 +1,73 @@ +name: Docker Build and Publish + +on: + push: + branches: + - main + - dev + tags: + - "v*" + pull_request: + branches: + - main + +env: + REGISTRY: ghcr.io + IMAGE_NAME: ${{ github.repository }} + +jobs: + build: + runs-on: self-hosted + permissions: + contents: read + packages: write + + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + + - name: Log in to Container Registry + if: github.event_name != 'pull_request' + uses: docker/login-action@v3 + with: + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + + - name: Extract metadata + id: meta + uses: docker/metadata-action@v5 + with: + images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} + tags: | + type=ref,event=branch + type=ref,event=pr + type=semver,pattern={{version}} + type=semver,pattern={{major}}.{{minor}} + type=semver,pattern={{major}} + type=raw,value=latest,enable={{is_default_branch}} + type=sha,prefix={{branch}}- + + - name: Build and push Docker image + uses: docker/build-push-action@v5 + with: + context: . + platforms: linux/amd64,linux/arm64 + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + cache-from: type=gha + cache-to: type=gha,mode=max + build-args: | + SOURCE_COMMIT=${{ github.sha }} + + - name: Generate artifact attestation + if: github.event_name != 'pull_request' + uses: actions/attest-build-provenance@v1 + with: + subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}} + subject-digest: ${{ steps.build.outputs.digest }} + push-to-registry: true diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..abc4b20 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,67 @@ +FROM node:20-alpine AS builder + +WORKDIR /app + +RUN npm install -g pnpm + +COPY package.json pnpm-lock.yaml ./ + +RUN pnpm install --frozen-lockfile + +COPY src ./src +COPY scripts ./scripts +COPY locales ./locales +COPY migrations ./migrations +COPY tsconfig.json ./ +COPY eslint.config.mjs ./ + +RUN pnpm run build + +WORKDIR /app/web + +COPY web/package.json web/pnpm-lock.yaml ./ + +RUN pnpm install --frozen-lockfile +COPY web/src ./src +COPY web/public ./public +COPY web/index.html ./ +COPY web/vite.config.ts ./ +COPY web/tsconfig.json ./ +COPY web/tsconfig.node.json ./ +COPY web/tailwind.config.js ./ +COPY web/postcss.config.js ./ + +RUN pnpm run build + +FROM node:20-alpine AS production + + +RUN addgroup -g 1001 -S nodejs && \ + adduser -S aethel -u 1001 + +WORKDIR /app + +RUN npm install -g pnpm + +COPY package.json pnpm-lock.yaml ./ + +RUN pnpm install --frozen-lockfile --prod && \ + pnpm store prune + +COPY --from=builder --chown=aethel:nodejs /app/dist ./dist +COPY --from=builder --chown=aethel:nodejs /app/locales ./locales +COPY --from=builder --chown=aethel:nodejs /app/migrations ./migrations +COPY --from=builder --chown=aethel:nodejs /app/scripts ./scripts + +COPY --from=builder --chown=aethel:nodejs /app/web/dist ./web/dist + +RUN mkdir -p /app/logs && chown aethel:nodejs /app/logs + +USER aethel + +EXPOSE 2020 + +HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ + CMD node -e "process.exit(0)" || exit 1 + +CMD ["pnpm", "run", "start"] diff --git a/docker-compose.example.yml b/docker-compose.example.yml new file mode 100644 index 0000000..5f1b3a6 --- /dev/null +++ b/docker-compose.example.yml @@ -0,0 +1,58 @@ +version: "3.8" + +services: + aethel: + image: ghcr.io/aethel-labs/aethel:latest + container_name: aethel-bot + restart: unless-stopped + environment: + TOKEN: your_discord_bot_token_here + CLIENT_ID: your_discord_client_id_here + DATABASE_URL: postgresql://username:password@postgres:5432/aethel + API_KEY_ENCRYPTION_SECRET: your_32_character_encryption_secret_here + OPENROUTER_API_KEY: your_openrouter_api_key_here + OPENWEATHER_API_KEY: your_openweather_api_key_here + ALLOWED_ORIGINS: http://localhost:3000,https://your-frontend-domain.com + STATUS_API_KEY: your_status_api_key_here + LOG_LEVEL: info + NODE_ENV: production + PORT: 2020 + SOURCE_COMMIT: latest + RATE_LIMIT_WINDOW_MS: 900000 + RATE_LIMIT_MAX: 100 + AI_EXEMPT_USER_ID: your_discord_user_id_for_unlimited_ai + JWT_SECRET: your_jwt_secret_key_here + DISCORD_CLIENT_SECRET: your_discord_oauth_client_secret + DISCORD_REDIRECT_URI: http://localhost:2020/api/auth/discord/callback + FRONTEND_URL: http://localhost:3000 + ports: + - "2020:2020" + depends_on: + - postgres + volumes: + - aethel_logs:/app/logs + networks: + - aethel_network + + postgres: + image: postgres:15-alpine + container_name: aethel-postgres + restart: unless-stopped + environment: + POSTGRES_DB: aethel + POSTGRES_USER: username + POSTGRES_PASSWORD: password + volumes: + - postgres_data:/var/lib/postgresql/data + networks: + - aethel_network + ports: + - "5432:5432" + +volumes: + postgres_data: + aethel_logs: + +networks: + aethel_network: + driver: bridge -- 2.51.2 From e28f53146062f87f245020873969dca3aac519f0 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:07:18 -0800 Subject: [PATCH 2/9] fix: simplify Docker workflow to avoid buildx permission issues --- .github/workflows/docker.yml | 33 +++++++++++---------------------- 1 file changed, 11 insertions(+), 22 deletions(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index ae53b64..b1d05e3 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -26,9 +26,6 @@ jobs: - name: Checkout repository uses: actions/checkout@v4 - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - name: Log in to Container Registry if: github.event_name != 'pull_request' uses: docker/login-action@v3 @@ -52,22 +49,14 @@ jobs: type=sha,prefix={{branch}}- - name: Build and push Docker image - uses: docker/build-push-action@v5 - with: - context: . - platforms: linux/amd64,linux/arm64 - push: ${{ github.event_name != 'pull_request' }} - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - cache-from: type=gha - cache-to: type=gha,mode=max - build-args: | - SOURCE_COMMIT=${{ github.sha }} - - - name: Generate artifact attestation - if: github.event_name != 'pull_request' - uses: actions/attest-build-provenance@v1 - with: - subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME}} - subject-digest: ${{ steps.build.outputs.digest }} - push-to-registry: true + run: | + docker build \ + --build-arg SOURCE_COMMIT=${{ github.sha }} \ + --tag ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} \ + --tag ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest \ + . + + if [ "${{ github.event_name }}" != "pull_request" ]; then + docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} + docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest + fi -- 2.51.2 From e8b35976c74a3eee839fbb29b116d10377f9fa8e Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:08:56 -0800 Subject: [PATCH 3/9] fix: restore Docker Buildx setup for proper GitHub Actions permissions --- .github/workflows/docker.yml | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index b1d05e3..27dbea7 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -26,6 +26,9 @@ jobs: - name: Checkout repository uses: actions/checkout@v4 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + - name: Log in to Container Registry if: github.event_name != 'pull_request' uses: docker/login-action@v3 @@ -49,14 +52,11 @@ jobs: type=sha,prefix={{branch}}- - name: Build and push Docker image - run: | - docker build \ - --build-arg SOURCE_COMMIT=${{ github.sha }} \ - --tag ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} \ - --tag ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest \ - . - - if [ "${{ github.event_name }}" != "pull_request" ]; then - docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} - docker push ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest - fi + uses: docker/build-push-action@v5 + with: + context: . + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + SOURCE_COMMIT=${{ github.sha }} -- 2.51.2 From 0b72b1f8f0d54ad604fa2f694196259b70116ab5 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:11:19 -0800 Subject: [PATCH 4/9] fix: kaniko --- .github/workflows/docker.yml | 29 +++++++++++++++++------------ 1 file changed, 17 insertions(+), 12 deletions(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 27dbea7..3ad9434 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -17,7 +17,7 @@ env: jobs: build: - runs-on: self-hosted + runs-on: ubuntu-latest permissions: contents: read packages: write @@ -26,9 +26,6 @@ jobs: - name: Checkout repository uses: actions/checkout@v4 - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v3 - - name: Log in to Container Registry if: github.event_name != 'pull_request' uses: docker/login-action@v3 @@ -49,14 +46,22 @@ jobs: type=semver,pattern={{major}}.{{minor}} type=semver,pattern={{major}} type=raw,value=latest,enable={{is_default_branch}} - type=sha,prefix={{branch}}- - - name: Build and push Docker image - uses: docker/build-push-action@v5 + - name: Build with Kaniko + if: github.event_name != 'pull_request' + uses: aevea/action-kaniko@master with: - context: . - push: ${{ github.event_name != 'pull_request' }} - tags: ${{ steps.meta.outputs.tags }} - labels: ${{ steps.meta.outputs.labels }} - build-args: | + registry: ${{ env.REGISTRY }} + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + image: ${{ env.IMAGE_NAME }} + tag: ${{ github.ref_name }} + tag_with_latest: ${{ github.ref == 'refs/heads/main' }} + build_args: | SOURCE_COMMIT=${{ github.sha }} + + - name: Build for PR (no push) + if: github.event_name == 'pull_request' + run: | + echo "PR build - image would be built but not pushed" + echo "Image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.head_ref }}" -- 2.51.2 From af299733f7ee33f77eda73a4fce6eff7ecc06697 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:13:13 -0800 Subject: [PATCH 5/9] fix: use proper Docker Buildx setup with install flag --- .github/workflows/docker.yml | 30 ++++++++++++++---------------- 1 file changed, 14 insertions(+), 16 deletions(-) diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 3ad9434..c7d1f36 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -26,6 +26,11 @@ jobs: - name: Checkout repository uses: actions/checkout@v4 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@v3 + with: + install: true + - name: Log in to Container Registry if: github.event_name != 'pull_request' uses: docker/login-action@v3 @@ -47,21 +52,14 @@ jobs: type=semver,pattern={{major}} type=raw,value=latest,enable={{is_default_branch}} - - name: Build with Kaniko - if: github.event_name != 'pull_request' - uses: aevea/action-kaniko@master + - name: Build and push Docker image + uses: docker/build-push-action@v5 with: - registry: ${{ env.REGISTRY }} - username: ${{ github.actor }} - password: ${{ secrets.GITHUB_TOKEN }} - image: ${{ env.IMAGE_NAME }} - tag: ${{ github.ref_name }} - tag_with_latest: ${{ github.ref == 'refs/heads/main' }} - build_args: | + context: . + push: ${{ github.event_name != 'pull_request' }} + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | SOURCE_COMMIT=${{ github.sha }} - - - name: Build for PR (no push) - if: github.event_name == 'pull_request' - run: | - echo "PR build - image would be built but not pushed" - echo "Image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.head_ref }}" + cache-from: type=gha + cache-to: type=gha,mode=max -- 2.51.2 From a3d6bac35dbad03f30e18d6196bed9a895954b37 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:14:18 -0800 Subject: [PATCH 6/9] fix: remove eslint config from Dockerfile build step --- Dockerfile | 1 - 1 file changed, 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index abc4b20..2b22d6a 100644 --- a/Dockerfile +++ b/Dockerfile @@ -13,7 +13,6 @@ COPY scripts ./scripts COPY locales ./locales COPY migrations ./migrations COPY tsconfig.json ./ -COPY eslint.config.mjs ./ RUN pnpm run build -- 2.51.2 From 374c22929fbf8a7b52ba2d8d5edd343266985727 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:16:41 -0800 Subject: [PATCH 7/9] fix: dockerignore --- .dockerignore | 1 - 1 file changed, 1 deletion(-) diff --git a/.dockerignore b/.dockerignore index 30c509f..bd4047f 100644 --- a/.dockerignore +++ b/.dockerignore @@ -22,7 +22,6 @@ docs .eslintrc.* .prettierrc* .prettierignore -tsconfig.json eslint.config.mjs Dockerfile* docker-compose*.yml -- 2.51.2 From 43d1a71336a22ebd51d2b5356dffdfc498f4f285 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:38:01 -0800 Subject: [PATCH 8/9] fix: listen to coderabit --- Dockerfile | 3 +++ docker-compose.example.yml | 27 ++------------------------- 2 files changed, 5 insertions(+), 25 deletions(-) diff --git a/Dockerfile b/Dockerfile index 2b22d6a..5a97b9b 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,8 @@ FROM node:20-alpine AS builder +ARG SOURCE_COMMIT +ENV SOURCE_COMMIT=${SOURCE_COMMIT} + WORKDIR /app RUN npm install -g pnpm diff --git a/docker-compose.example.yml b/docker-compose.example.yml index 5f1b3a6..d99004d 100644 --- a/docker-compose.example.yml +++ b/docker-compose.example.yml @@ -1,36 +1,14 @@ -version: "3.8" - services: aethel: image: ghcr.io/aethel-labs/aethel:latest container_name: aethel-bot restart: unless-stopped - environment: - TOKEN: your_discord_bot_token_here - CLIENT_ID: your_discord_client_id_here - DATABASE_URL: postgresql://username:password@postgres:5432/aethel - API_KEY_ENCRYPTION_SECRET: your_32_character_encryption_secret_here - OPENROUTER_API_KEY: your_openrouter_api_key_here - OPENWEATHER_API_KEY: your_openweather_api_key_here - ALLOWED_ORIGINS: http://localhost:3000,https://your-frontend-domain.com - STATUS_API_KEY: your_status_api_key_here - LOG_LEVEL: info - NODE_ENV: production - PORT: 2020 - SOURCE_COMMIT: latest - RATE_LIMIT_WINDOW_MS: 900000 - RATE_LIMIT_MAX: 100 - AI_EXEMPT_USER_ID: your_discord_user_id_for_unlimited_ai - JWT_SECRET: your_jwt_secret_key_here - DISCORD_CLIENT_SECRET: your_discord_oauth_client_secret - DISCORD_REDIRECT_URI: http://localhost:2020/api/auth/discord/callback - FRONTEND_URL: http://localhost:3000 + env_file: + - .env ports: - "2020:2020" depends_on: - postgres - volumes: - - aethel_logs:/app/logs networks: - aethel_network @@ -51,7 +29,6 @@ services: volumes: postgres_data: - aethel_logs: networks: aethel_network: -- 2.51.2 From b3ac1f9d37c84ecbe9826601682c5eaf803f23a3 Mon Sep 17 00:00:00 2001 From: scanash00 Date: Fri, 8 Aug 2025 12:38:05 -0800 Subject: [PATCH 9/9] Update Dockerfile --- Dockerfile | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 5a97b9b..8694896 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,10 +2,12 @@ FROM node:20-alpine AS builder ARG SOURCE_COMMIT ENV SOURCE_COMMIT=${SOURCE_COMMIT} +ENV NODE_ENV=production WORKDIR /app -RUN npm install -g pnpm +RUN corepack enable +RUN corepack prepare pnpm@latest --activate COPY package.json pnpm-lock.yaml ./ -- 2.51.2