# Multi-stage build for the beheer portal (Angular → Caddy). # Build context is the repo root (the app needs the pnpm workspace + libs). See infra/docker-compose.yml. FROM node:24-slim AS build WORKDIR /src RUN corepack enable && corepack prepare pnpm@11.5.2 --activate # Restore first (cached unless the manifests change). COPY package.json pnpm-lock.yaml pnpm-workspace.yaml nx.json tsconfig.base.json eslint.config.mjs ./ RUN pnpm install --frozen-lockfile # Sources (only what the app + its libs need). COPY apps/beheer apps/beheer COPY libs libs RUN pnpm nx build beheer FROM caddy:2-alpine AS runtime COPY apps/beheer/Caddyfile /etc/caddy/Caddyfile COPY --from=build /src/dist/apps/beheer/browser /usr/share/caddy # Compose-time OIDC config: the browser (Playwright, on the compose network) reaches Keycloak by # service name, so the token issuer matches the BFF's medewerker authority (host-consistent, ADR-0013). # Kubernetes mounts a ConfigMap over this file with the node address instead (ADR-0033). RUN printf '{ "authority": "http://keycloak:8080/realms/medewerker" }\n' > /usr/share/caddy/config.json EXPOSE 80