diff --git a/backend/Dockerfile b/backend/Dockerfile index c04e054..a1ffc62 100644 --- a/backend/Dockerfile +++ b/backend/Dockerfile @@ -1,4 +1,6 @@ FROM node:20-alpine AS base +# Prisma migration engine requires OpenSSL +RUN apk add --no-cache openssl WORKDIR /app COPY package*.json ./ RUN npm ci --only=production @@ -9,9 +11,12 @@ COPY . . CMD ["npm", "run", "dev"] FROM base AS prod +# Install prisma CLI for migrate deploy at runtime +RUN npm install prisma --save-dev COPY . . -# Generate Prisma client in the production image +# Generate Prisma Client RUN npx prisma generate -# Run as non-root user +# Fix ownership so the node user can write engine cache +RUN chown -R node:node /app USER node -CMD ["node", "src/index.js"] +CMD ["/bin/sh", "/app/docker-entrypoint.sh"] diff --git a/backend/prisma/schema.prisma b/backend/prisma/schema.prisma index 19056b0..6b4d19d 100644 --- a/backend/prisma/schema.prisma +++ b/backend/prisma/schema.prisma @@ -1,5 +1,6 @@ generator client { - provider = "prisma-client-js" + provider = "prisma-client-js" + binaryTargets = ["native", "linux-musl-openssl-3.0.x"] } datasource db { diff --git a/docker-compose.yml b/docker-compose.yml index e78733a..9124540 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -34,16 +34,16 @@ services: NODE_ENV: production PORT: 3001 CORS_ORIGIN: "http://localhost:52867" - # Run as non-root - user: "node" + # Non-root user set in Dockerfile; entrypoint runs migrations then starts server entrypoint: ["/bin/sh", "/app/docker-entrypoint.sh"] ports: - "3001:3001" healthcheck: - test: ["CMD-SHELL", "wget -qO- http://localhost:3001/health || exit 1"] - interval: 15s + test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:3001/health || exit 1"] + interval: 10s timeout: 5s - retries: 5 + retries: 10 + start_period: 40s frontend: build: