28 lines
1.3 KiB
Docker
28 lines
1.3 KiB
Docker
# Multi-stage build for the beheer portal (Angular → nginx).
|
|
# Build context is the repo root (the app needs the pnpm workspace + libs). See infra/docker-compose.yml.
|
|
FROM node:24-slim AS build
|
|
WORKDIR /src
|
|
RUN corepack enable && corepack prepare pnpm@11.5.2 --activate
|
|
|
|
# Restore first (cached unless the manifests change).
|
|
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml nx.json tsconfig.base.json eslint.config.mjs ./
|
|
RUN pnpm install --frozen-lockfile
|
|
|
|
# Sources (only what the app + its libs need).
|
|
COPY apps/beheer apps/beheer
|
|
COPY libs libs
|
|
RUN pnpm nx build beheer
|
|
|
|
FROM nginx:1.27-alpine AS runtime
|
|
COPY apps/beheer/nginx.conf /etc/nginx/conf.d/default.conf
|
|
COPY --from=build /src/dist/apps/beheer/browser /usr/share/nginx/html
|
|
# Compose-time OIDC config: the browser (Playwright, on the compose network) reaches Keycloak by
|
|
# service name, so the token issuer matches the BFF's medewerker authority (host-consistent, ADR-0013).
|
|
RUN printf '{ "authority": "http://keycloak:8080/realms/medewerker" }\n' > /usr/share/nginx/html/config.json
|
|
# Make the reverse-proxy resolver engine-portable (Docker 127.0.0.11 vs podman aardvark); runs from
|
|
# the nginx image's /docker-entrypoint.d before nginx starts.
|
|
COPY apps/portal-nginx-resolver.sh /docker-entrypoint.d/40-resolver.sh
|
|
RUN chmod +x /docker-entrypoint.d/40-resolver.sh
|
|
|
|
EXPOSE 80
|