Files
OpenMAIC/Dockerfile
T
wyucandClaude Opus 5 f67e708c03 docs(docker): describe what the builder heap limit does and does not bound (#1607)
The comment implied the old-space limit prevents a VM-level OOM. It only
makes the V8 heap limit explicit; measurements showed the package build
completing under a 1 GiB container limit, not a guarantee against host OOM.


Claude-Session: https://claude.ai/code/session_01DYifP8wM4XJQ3Hc2qsF6zf

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-20 04:08:42 +08:00

135 lines
4.9 KiB
Docker

# syntax=docker/dockerfile:1
# ---- Stage 1: Base ----
FROM node:22-alpine AS base
ARG ALPINE_MIRROR=""
ARG NPM_REGISTRY=""
RUN if [ -n "$ALPINE_MIRROR" ]; then \
sed -i "s|dl-cdn.alpinelinux.org|$ALPINE_MIRROR|g" /etc/apk/repositories; \
fi && \
apk add --no-cache libc6-compat
RUN npm_registry="$NPM_REGISTRY"; \
while [ "${npm_registry%/}" != "$npm_registry" ]; do \
npm_registry="${npm_registry%/}"; \
done; \
if [ -n "$npm_registry" ]; then \
export COREPACK_NPM_REGISTRY="$npm_registry"; \
fi && \
corepack enable && \
corepack prepare pnpm@10.28.0 --activate
WORKDIR /app
# ---- Stage 2: Dependencies ----
FROM base AS deps
ARG NPM_REGISTRY
# Native build tools for sharp, @napi-rs/canvas
RUN apk add --no-cache python3 build-base g++ cairo-dev pango-dev jpeg-dev giflib-dev librsvg-dev
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
COPY packages/ ./packages/
COPY scripts/ ./scripts/
RUN --mount=type=cache,id=pnpm-store,target=/root/.local/share/pnpm/store \
npm_registry="$NPM_REGISTRY"; \
while [ "${npm_registry%/}" != "$npm_registry" ]; do \
npm_registry="${npm_registry%/}"; \
done; \
if [ -n "$npm_registry" ]; then \
pnpm config set registry "$npm_registry"; \
fi && \
pnpm install --frozen-lockfile --ignore-scripts
# ---- Stage 3: Builder ----
FROM base AS builder
ARG ALLOWED_FRAME_ANCESTORS
ARG NEXT_PUBLIC_PERSISTENCE
ARG NEXT_PUBLIC_PERSISTENCE_TOKEN
ARG NEXT_PUBLIC_MAIC_EDITOR_ENABLED
ARG NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED
ARG NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED
ARG NEXT_PUBLIC_PI_CHAT_ENABLED
ARG NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED
ARG NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI
ARG NEXT_PUBLIC_ENABLE_VIDEO_EXPORT
ARG NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION
ARG NEXT_PUBLIC_ENABLE_PPTX_IMPORT
ARG NEXT_PUBLIC_PRO_WORKBENCH_ENABLED
ENV ALLOWED_FRAME_ANCESTORS=$ALLOWED_FRAME_ANCESTORS
ENV NEXT_PUBLIC_PERSISTENCE=$NEXT_PUBLIC_PERSISTENCE
ENV NEXT_PUBLIC_PERSISTENCE_TOKEN=$NEXT_PUBLIC_PERSISTENCE_TOKEN
ENV NEXT_PUBLIC_MAIC_EDITOR_ENABLED=$NEXT_PUBLIC_MAIC_EDITOR_ENABLED
ENV NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED=$NEXT_PUBLIC_MAIC_EDITOR_RENDERER_ENABLED
ENV NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED=$NEXT_PUBLIC_MAIC_PLAYBACK_RENDERER_ENABLED
ENV NEXT_PUBLIC_PI_CHAT_ENABLED=$NEXT_PUBLIC_PI_CHAT_ENABLED
ENV NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED=$NEXT_PUBLIC_COURSEWARE_REFERENCE_ENABLED
ENV NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI=$NEXT_PUBLIC_SHOW_VOCATIONAL_TEST_UI
ENV NEXT_PUBLIC_ENABLE_VIDEO_EXPORT=$NEXT_PUBLIC_ENABLE_VIDEO_EXPORT
ENV NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION=$NEXT_PUBLIC_VIDEO_EXPORT_CTA_DESTINATION
ENV NEXT_PUBLIC_ENABLE_PPTX_IMPORT=$NEXT_PUBLIC_ENABLE_PPTX_IMPORT
ENV NEXT_PUBLIC_PRO_WORKBENCH_ENABLED=$NEXT_PUBLIC_PRO_WORKBENCH_ENABLED
COPY --from=deps /app/node_modules ./node_modules
COPY --from=deps /app/packages ./packages
COPY . .
# Build the workspace packages (rollup + tsc) here, not inside `pnpm install`,
# so the deps stage only resolves and links dependencies. The importer's
# rollup + terser pass is the heaviest step (see #1526). This is the same chain
# the root `postinstall` runs locally, so local dev is unchanged.
# The explicit V8 old-space size makes the heap limit predictable instead of
# derived from the container's memory limit; with it, this step completes under
# a 1 GiB container limit. It bounds the JS heap only, not the step's total
# memory, so it does not by itself prevent a host- or VM-level OOM.
RUN NODE_OPTIONS=--max-old-space-size=1024 pnpm run build:packages
RUN pnpm build
# ---- Stage 4: Runner ----
FROM node:22-alpine AS runner
ARG ALPINE_MIRROR=""
WORKDIR /app
ENV NODE_ENV=production
ENV HOSTNAME=0.0.0.0
ENV PORT=3000
RUN if [ -n "$ALPINE_MIRROR" ]; then \
cp /etc/apk/repositories /tmp/apk.repositories; \
sed -i "s|dl-cdn.alpinelinux.org|$ALPINE_MIRROR|g" /etc/apk/repositories; \
fi && \
apk add --no-cache libc6-compat cairo pango jpeg giflib librsvg && \
if [ -n "$ALPINE_MIRROR" ]; then \
mv /tmp/apk.repositories /etc/apk/repositories; \
fi
RUN addgroup --system --gid 1001 nodejs && \
adduser --system --uid 1001 nextjs
COPY --from=builder /app/public ./public
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
# The app persists classrooms, classroom media, and usage records under
# ./data, which docker-compose.yml mounts as the openmaic-data named volume.
# Nothing above creates the directory, so on first run Docker materializes
# the mountpoint as root:root and every write from the unprivileged runtime
# user fails with EACCES — classroom persistence silently stores nothing
# (THU-MAIC/OpenMAIC#1438). Creating it here makes the empty-volume copy-up
# inherit the runtime user's ownership.
RUN mkdir -p /app/data && chown -R nextjs:nodejs /app/data
USER nextjs
EXPOSE 3000
CMD ["node", "server.js"]