mirror of
https://github.com/tiennm99/ccs.git
synced 2026-10-11 03:13:12 +00:00
Fixes from maintainer review: .dockerignore: - Add .env* files to prevent secret leakage (CRITICAL) - Add tests/, docs/, IDE files to reduce build context - Add organized comments for maintainability Dockerfile: - Pin bun version (ARG BUN_VERSION=1.2.2) for reproducible builds - Add build artifact validation step - Add npm cache clean to reduce image size - Add section comments for readability docker-compose.yml: - Add grok_home volume for grok-cli persistence - Add start_period to healthcheck for slow starts - Add resource limits (1G RAM, 2 CPUs) with reservations - Add documentation comments entrypoint.sh: - Improve chown error handling with warning message - Add usage help when no command provided README.md: - Add Resource Limits section with examples - Add Graceful Shutdown documentation - Add Troubleshooting section (permissions, ports, restart loops) - Add Security Notes section - Update persistence docs to include grok-cli Co-authored-by: opastorello <nicolas@pastorello-lab.com.br>
86 lines
2.7 KiB
Docker
86 lines
2.7 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# =============================================================================
|
|
# Build stage: compile TypeScript and build UI
|
|
# =============================================================================
|
|
FROM node:20-bookworm-slim AS build
|
|
|
|
SHELL ["/bin/bash", "-lc"]
|
|
|
|
# Pin bun version for reproducible builds
|
|
ARG BUN_VERSION=1.2.2
|
|
ENV BUN_INSTALL=/usr/local/bun
|
|
ENV PATH="$BUN_INSTALL/bin:$PATH"
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends curl ca-certificates unzip \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install specific bun version
|
|
RUN curl -fsSL https://bun.sh/install | bash -s "bun-v${BUN_VERSION}"
|
|
|
|
WORKDIR /app
|
|
|
|
# Dependency install layer (avoid running install scripts inside the image build)
|
|
COPY package.json bun.lock bunfig.toml ./
|
|
COPY ui/package.json ui/bun.lock ./ui/
|
|
|
|
RUN bun install --frozen-lockfile --ignore-scripts \
|
|
&& (cd ui && bun install --frozen-lockfile --ignore-scripts)
|
|
|
|
COPY . .
|
|
|
|
RUN bun run build:all
|
|
|
|
# Validate build artifacts exist
|
|
RUN test -d dist && test -d lib && echo "[OK] Build artifacts validated"
|
|
|
|
# =============================================================================
|
|
# Runtime stage: minimal production image
|
|
# =============================================================================
|
|
FROM node:20-bookworm-slim AS runtime
|
|
|
|
SHELL ["/bin/bash", "-lc"]
|
|
|
|
# Pin bun version for reproducible builds
|
|
ARG BUN_VERSION=1.2.2
|
|
ENV BUN_INSTALL=/usr/local/bun
|
|
ENV PATH="$BUN_INSTALL/bin:/home/node/.opencode/bin:$PATH"
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends curl ca-certificates unzip \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install specific bun version
|
|
RUN curl -fsSL https://bun.sh/install | bash -s "bun-v${BUN_VERSION}"
|
|
|
|
WORKDIR /app
|
|
|
|
COPY package.json bun.lock ./
|
|
RUN bun install --frozen-lockfile --production --ignore-scripts
|
|
|
|
COPY docker/entrypoint.sh /usr/local/bin/ccs-entrypoint
|
|
RUN chmod +x /usr/local/bin/ccs-entrypoint
|
|
|
|
COPY --from=build /app/dist ./dist
|
|
COPY --from=build /app/lib ./lib
|
|
COPY --from=build /app/config ./config
|
|
COPY --from=build /app/scripts ./scripts
|
|
COPY --from=build /app/README.md ./README.md
|
|
COPY --from=build /app/LICENSE ./LICENSE
|
|
|
|
# Install AI CLI tools (using latest - pin versions in production if needed)
|
|
# These are optional tools for docker exec usage
|
|
RUN npm install -g @google/gemini-cli @vibe-kit/grok-cli @anthropic-ai/claude-code \
|
|
&& npm install -g @kaitranntt/ccs --force \
|
|
&& npm cache clean --force \
|
|
&& su -s /bin/bash node -c 'curl -fsSL https://opencode.ai/install | bash -s -- --no-modify-path' \
|
|
&& ln -sf /app/dist/ccs.js /usr/local/bin/ccs
|
|
|
|
ENV CCS_PORT=3000
|
|
EXPOSE 3000 8317
|
|
|
|
ENTRYPOINT ["/usr/local/bin/ccs-entrypoint"]
|
|
|
|
CMD ["bash", "-c", "node dist/ccs.js config --port ${CCS_PORT}"]
|