Archived
build-and-publish / build (push) Successful in 1m9s
Replaces the Next.js app. Same site, same look; the parts that were decisions rather than markup now live in Java. - catalogue, curated order, category filter and image URLs move from a TypeScript array into Postgres behind /api/products and /api/categories - contact form uses the shared platform-starter-contact: validate, RECORD, send, then fan out to n8n. Recording first means a relay outage costs a notification, not an enquiry - PageMetaController rewrites title/description/OG per route, replacing what Next's SSR gave crawlers and link-preview scrapers - 50MB of photos leave the repo for the MinIO bucket, re-encoded to webp (14MB) with EXIF (including phone GPS) stripped - fixes a catalogue typo: 'Strawberry Pie' was category 'Pies', which no filter matched, so it was unreachable unless browsing All Co-Authored-By: Claude Opus 4.8 <[email protected]> Claude-Session: https://claude.ai/code/session_01XXKjx7FNyRVAjU8dgB5KhN
38 lines
1.7 KiB
Docker
38 lines
1.7 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# ---------- build ----------
|
|
FROM maven:3.9-eclipse-temurin-25 AS build
|
|
WORKDIR /src
|
|
COPY . .
|
|
# Resolve the platform from the Gitea Maven registry (creds via BuildKit secrets); the Maven build also
|
|
# runs the Vite/React SPA build (frontend-maven-plugin) and folds it into the jar. Tests are skipped here
|
|
# because Testcontainers needs a Docker daemon — they run via `mvn verify`, not in the image build.
|
|
RUN --mount=type=secret,id=maven_user --mount=type=secret,id=maven_token \
|
|
MAVEN_USER="$(cat /run/secrets/maven_user)" MAVEN_TOKEN="$(cat /run/secrets/maven_token)" \
|
|
mvn -B -ntp -s .gitea/ci-settings.xml -DskipTests package \
|
|
&& cp "$(ls target/itsthevine-*.jar | grep -v original | head -1)" app.jar \
|
|
&& java -Djarmode=tools -jar app.jar extract --layers --destination extracted
|
|
|
|
# ---------- runtime ----------
|
|
FROM eclipse-temurin:25-jre-alpine AS runtime
|
|
RUN apk -U upgrade --no-cache && apk add --no-cache curl
|
|
RUN addgroup -S spring && adduser -S -D -H -h /app -s /sbin/nologin -G spring spring
|
|
WORKDIR /app
|
|
|
|
COPY --from=build --chown=spring:spring /src/extracted/dependencies/ ./
|
|
COPY --from=build --chown=spring:spring /src/extracted/snapshot-dependencies/ ./
|
|
COPY --from=build --chown=spring:spring /src/extracted/application/ ./
|
|
|
|
USER spring
|
|
EXPOSE 8080
|
|
|
|
HEALTHCHECK --interval=30s --timeout=3s --start-period=40s --retries=3 \
|
|
CMD curl -fsS http://localhost:8080/actuator/health || exit 1
|
|
|
|
ARG GIT_SHA=unknown
|
|
LABEL org.opencontainers.image.title="itsthevine" \
|
|
org.opencontainers.image.source="https://git.thebennett.net/thevine/itsthevine" \
|
|
org.opencontainers.image.revision="${GIT_SHA}"
|
|
|
|
ENTRYPOINT ["java", "-XX:MaxRAMPercentage=75.0", "-jar", "app.jar"]
|