Introduce AGENTS.md (root, primary agent instruction file) documenting six hard-won fixes with explicit DO NOT / WHY, plus executable enforcement so a future AI cannot delete or reintroduce them: 1. package-lock.json must be generated with npm 10 (Docker's npm 10.9.8). npm 11 drops the top-level @emnapi/core + @emnapi/runtime entries npm 10 needs, breaking the tag-triggered Docker build at `npm ci` (happened on v1.0.14). Add scripts/verify-lockfile-npm10.mjs + .npmrc + a Dockerfile fail-fast check + a CI step + tests/unit/lockfile-npm10-guard.test.js. Also re-fix the lockfile itself (regenerated with npm 10.9.8). 2. Tests must never write to the real ~/.9router DB (isolateDataDir). 3. Hidden providers must not leak into Usage (usageProviders !p.hidden). 4. codebuddy-intl connection test + OAuth identity. 5. Fork-only features that must survive upstream syncs. 6. Upstream sync procedure. Each marker cross-references AGENTS.md and the covering test. CLAUDE.md now points to AGENTS.md at the top. Verified: build ok, guard script passes, full suite leaves the real DB count unchanged (38), 0 new regressions.
72 lines
3.4 KiB
Docker
72 lines
3.4 KiB
Docker
# syntax=docker/dockerfile:1.7
|
|
# Pinned by digest so a base-image refresh cannot silently bump npm and break
|
|
# `npm ci` against the committed lockfile (see v1.0.9 npm ci EUSAGE failure).
|
|
# DO NOT unpin. This image ships npm 10.9.8 — the lockfile MUST be regenerated
|
|
# with npm 10 (`npx -y npm@10.9.8 install --package-lock-only`), never npm 11+.
|
|
# See AGENTS.md §1 and scripts/verify-lockfile-npm10.mjs.
|
|
ARG NODE_IMAGE=node:22-alpine@sha256:c610fcdfb1d5b4740dd70c284ed3cb16bb857e0f7166196e36a5501df7a3aa32
|
|
FROM ${NODE_IMAGE} AS base
|
|
WORKDIR /app
|
|
|
|
FROM base AS builder
|
|
|
|
RUN apk --no-cache upgrade && apk --no-cache add python3 make g++ linux-headers
|
|
|
|
COPY package.json package-lock.json ./
|
|
# Fail fast with an actionable message if the lockfile was regenerated with
|
|
# npm 11+ (drops the top-level @emnapi entries npm 10 requires). Without this,
|
|
# `npm ci` still fails but with a cryptic "Missing: @emnapi/..." EUSAGE error.
|
|
RUN node -e "const l=require('./package-lock.json');const p=l.packages||{};const miss=['node_modules/@emnapi/core','node_modules/@emnapi/runtime'].filter(k=>!p[k]);if(miss.length){console.error('LOCKFILE NOT npm-10-COMPATIBLE — missing: '+miss.join(', '));console.error('Regenerate with: npx -y npm@10.9.8 install --package-lock-only');console.error('See AGENTS.md §1.');process.exit(1)}"
|
|
RUN --mount=type=cache,target=/root/.npm \
|
|
npm ci
|
|
|
|
COPY . ./
|
|
ENV NEXT_TELEMETRY_DISABLED=1
|
|
RUN npm run build
|
|
|
|
FROM ${NODE_IMAGE} AS runner
|
|
WORKDIR /app
|
|
|
|
LABEL org.opencontainers.image.title="9router"
|
|
|
|
ENV NODE_ENV=production
|
|
ENV PORT=20128
|
|
ENV HOSTNAME=0.0.0.0
|
|
ENV NEXT_TELEMETRY_DISABLED=1
|
|
ENV DATA_DIR=/app/data
|
|
|
|
COPY --from=builder /app/public ./public
|
|
COPY --from=builder /app/.next/static ./.next/static
|
|
COPY --from=builder /app/.next/standalone ./
|
|
COPY --from=builder /app/custom-server.js ./custom-server.js
|
|
COPY --from=builder /app/open-sse ./open-sse
|
|
# Next file tracing can omit sibling files; MITM runs server.js as a separate process.
|
|
COPY --from=builder /app/src/mitm ./src/mitm
|
|
# Standalone node_modules may omit deps only required by the MITM child process.
|
|
COPY --from=builder /app/node_modules/node-forge ./node_modules/node-forge
|
|
# Ensure `next` is available at runtime in case tracing did not include it.
|
|
COPY --from=builder /app/node_modules/next ./node_modules/next
|
|
# sql.js loads dist/sql-wasm.wasm by path at runtime; tracing only follows JS imports,
|
|
# so the last-resort DB driver would abort with ENOENT on the missing binary.
|
|
COPY --from=builder /app/node_modules/sql.js ./node_modules/sql.js
|
|
# node-machine-id is createRequire-loaded at runtime; tracing omits it.
|
|
COPY --from=builder /app/node_modules/node-machine-id ./node_modules/node-machine-id
|
|
|
|
RUN mkdir -p /app/data && chown -R node:node /app && \
|
|
mkdir -p /app/data-home && chown node:node /app/data-home && \
|
|
ln -sf /app/data-home /root/.9router 2>/dev/null || true
|
|
|
|
# Fix permissions at runtime (handles mounted volumes)
|
|
RUN apk --no-cache upgrade && apk --no-cache add su-exec && \
|
|
printf '#!/bin/sh\nchown -R node:node /app/data /app/data-home 2>/dev/null\nexec su-exec node "$@"\n' > /entrypoint.sh && \
|
|
chmod +x /entrypoint.sh
|
|
|
|
EXPOSE 20128
|
|
|
|
# Health: Next serves /api/health (dashboardGuard public path).
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
|
|
CMD node -e "fetch('http://127.0.0.1:20128/api/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"
|
|
|
|
ENTRYPOINT ["/entrypoint.sh"]
|
|
CMD ["node", "custom-server.js"]
|