# Multi-stage build for optimal production image # Stage 1: Dependencies FROM node:20-alpine AS deps RUN apk add --no-cache libc6-compat WORKDIR /app # Copy package files COPY package.json package-lock.json ./ # Install all dependencies (including dev dependencies needed for build) ENV NODE_ENV=development RUN npm ci # Stage 2: Builder FROM node:20-alpine AS builder WORKDIR /app # Copy dependencies from deps stage COPY --from=deps /app/node_modules ./node_modules COPY . . # Set environment variable for build (optional - can be overridden at runtime) ARG NEXT_PUBLIC_GEMINI_API_KEY ENV NEXT_PUBLIC_GEMINI_API_KEY=$NEXT_PUBLIC_GEMINI_API_KEY # Build Next.js application with standalone output ENV NEXT_TELEMETRY_DISABLED=1 RUN npm run build # Stage 3: Runner FROM node:20-alpine AS runner WORKDIR /app ENV NODE_ENV=production ENV NEXT_TELEMETRY_DISABLED=1 # Optional: OCI-Labels für GHCR LABEL org.opencontainers.image.source="https://github.com/stefan-kp/chess_tutor" LABEL org.opencontainers.image.title="Chess Tutor" LABEL org.opencontainers.image.description="AI-based chess tutor using Stockfish and Gemini" # Create non-root user for security RUN addgroup --system --gid 1001 nodejs RUN adduser --system --uid 1001 nextjs # Copy necessary files from builder COPY --from=builder /app/public ./public COPY --from=builder /app/.next/standalone ./ COPY --from=builder /app/.next/static ./.next/static # Set ownership to non-root user RUN chown -R nextjs:nodejs /app # Switch to non-root user USER nextjs # Expose port 3050 EXPOSE 3050 # Set port environment variable ENV PORT=3050 ENV HOSTNAME="0.0.0.0" # Health check HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ CMD node -e "require('http').get('http://localhost:3050/api/health', (r) => {process.exit(r.statusCode === 200 ? 0 : 1)})" || exit 1 # Start the application CMD ["node", "server.js"]