[READ-ONLY] Mirror of https://github.com/thoda-dev/shhh. Self-hostable zero-knowledge pastebin for secrets that expire on their own
docker end-to-end-encryption nuxt nuxtjs pastebin secrets selft-hosted zero-knowledge
Something went wrong. Try again.
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455# Build from the repo root: docker build -f docker/Dockerfile -t shhh .FROM node:24-alpine AS baseENV PNPM_HOME=/pnpmENV PATH=$PNPM_HOME:$PATHRUN corepack enableWORKDIR /app
FROM base AS deps# Manifests only, so this layer survives every source change.COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./COPY apps/app/package.json apps/app/COPY apps/docs/package.json apps/docs/RUN pnpm install --frozen-lockfile --filter app...
FROM deps AS buildCOPY . .# Not `pnpm build`: that script wraps Nuxt in an Infisical call this image has no use for.RUN pnpm --filter app exec nuxt build
# Not `FROM base`: inheriting the package managers is what drags their CVEs in.FROM node:24-alpine AS runtimeWORKDIR /app
# The base froze its Alpine packages on its build date; openssl has moved since.RUN apk upgrade --no-cache
# Nothing here runs a package manager, and scanners read the final filesystem.RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/lib/node_modules/corepack \ /usr/local/bin/npm /usr/local/bin/npx /usr/local/bin/corepack \ /usr/local/bin/pnpm /usr/local/bin/pnpx \ /usr/local/bin/yarn /usr/local/bin/yarnpkg /opt/yarn-v*
ENV NODE_ENV=productionENV NUXT_PORT=3000ENV NUXT_HOST=0.0.0.0ENV MIGRATIONS_DIR=/app/migrations
COPY --from=build /app/apps/app/.output ./.output
# Read from disk at boot by server/plugins/migrate.ts, so not part of Nitro's output.COPY --from=build /app/apps/app/server/database/migrations ./migrations
USER node
EXPOSE 3000
# The app's own endpoint, so an instance that lost its database reports unhealthy.HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \ CMD node -e "fetch('http://127.0.0.1:3000/api/health').then(r=>{if(!r.ok)process.exit(1)}).catch(()=>process.exit(1))"
CMD ["node", ".output/server/index.mjs"]