feat(deploy): production Dockerfiles, compose stack, and runbook
- Multi-stage Dockerfiles for web/api/generator (pnpm workspace install, tsx runtime — workspace packages are raw TS, same model as runner-template). - docker-compose.prod.yml: postgres + redis + the three app services. api/generator/web use host networking so the generator's host-port probe is correct and every service shares one address space; api + generator mount the Docker socket. Binds nothing on 80/443 — safe beside other apps. - Optional Traefik reverse proxy in infra/traefik/ (heavily gated — only if the box has no existing proxy). - .env.production.example, .dockerignore, DEPLOY.md (Cloudflare zone, GoDaddy nameserver switch, server deploy, Google Cloud Console OAuth app). - api/generator `start` now runs via tsx; `node dist/index.js` could never resolve the raw-TS workspace imports. All three images verified building clean; the API container boots under tsx. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
34
apps/generator/Dockerfile
Normal file
34
apps/generator/Dockerfile
Normal file
@@ -0,0 +1,34 @@
|
||||
# syntax=docker/dockerfile:1
|
||||
# Generator worker (BullMQ). Renders generated MCP servers, builds their Docker
|
||||
# images and runs them as sibling containers on the host daemon.
|
||||
# Build context must be the repo root: docker build -f apps/generator/Dockerfile .
|
||||
|
||||
FROM node:20-alpine AS base
|
||||
RUN corepack enable && corepack prepare pnpm@9.12.0 --activate
|
||||
WORKDIR /app
|
||||
|
||||
# ---- deps ----
|
||||
FROM base AS deps
|
||||
COPY pnpm-lock.yaml pnpm-workspace.yaml package.json ./
|
||||
COPY apps/api/package.json apps/api/
|
||||
COPY apps/web/package.json apps/web/
|
||||
COPY apps/generator/package.json apps/generator/
|
||||
COPY apps/runner-template/package.json apps/runner-template/
|
||||
COPY packages/auth/package.json packages/auth/
|
||||
COPY packages/db/package.json packages/db/
|
||||
COPY packages/llm/package.json packages/llm/
|
||||
COPY packages/types/package.json packages/types/
|
||||
RUN pnpm install --frozen-lockfile
|
||||
|
||||
# ---- runtime ----
|
||||
FROM deps AS runtime
|
||||
# docker CLI: the worker shells out to `docker build` / `docker run` against the
|
||||
# host daemon (socket mounted in compose). apps/runner-template is copied below
|
||||
# and used as the build context template for every generated server.
|
||||
RUN apk add --no-cache docker-cli
|
||||
ENV NODE_ENV=production
|
||||
COPY . .
|
||||
# build-context is a mounted volume at runtime; create the dir so the path exists.
|
||||
RUN mkdir -p /app/build-context
|
||||
WORKDIR /app/apps/generator
|
||||
CMD ["pnpm", "start"]
|
||||
@@ -5,7 +5,7 @@
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"dev": "tsx watch src/index.ts",
|
||||
"start": "node dist/index.js",
|
||||
"start": "tsx src/index.ts",
|
||||
"build": "tsc -p tsconfig.json",
|
||||
"typecheck": "tsc --noEmit"
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user