Skip to content

Commit

Permalink
docker + traefik config
Browse files Browse the repository at this point in the history
  • Loading branch information
gregrickaby committed Jan 19, 2025
1 parent 3d8f8a8 commit 93e56d3
Show file tree
Hide file tree
Showing 4 changed files with 108 additions and 2 deletions.
9 changes: 7 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -25,12 +25,17 @@ npm-debug.log*
yarn-debug.log*
yarn-error.log*

# local env files
.env*.local
# env files
.env
.env.local

# vercel
.vercel

# typescript
*.tsbuildinfo
next-env.d.ts

# letsencrypt
/.well-known
/letsencrypt
61 changes: 61 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# syntax=docker.io/docker/dockerfile:1

FROM node:22-alpine AS base

# Install dependencies only when needed
FROM base AS deps
# Check https://github.com/nodejs/docker-node/tree/b4117f9333da4138b03a546ec926ef50a31506c3#nodealpine to understand why libc6-compat might be needed.
RUN apk add --no-cache libc6-compat
WORKDIR /app

# Install dependencies based on the preferred package manager
COPY package.json yarn.lock* package-lock.json* pnpm-lock.yaml* .npmrc* ./
RUN \
if [ -f yarn.lock ]; then yarn --frozen-lockfile; \
elif [ -f package-lock.json ]; then npm ci; \
elif [ -f pnpm-lock.yaml ]; then corepack enable pnpm && pnpm i --frozen-lockfile; \
else echo "Lockfile not found." && exit 1; \
fi


# Rebuild the source code only when needed
FROM base AS builder
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .

RUN \
if [ -f yarn.lock ]; then yarn run build; \
elif [ -f package-lock.json ]; then npm run build; \
elif [ -f pnpm-lock.yaml ]; then corepack enable pnpm && pnpm run build; \
else echo "Lockfile not found." && exit 1; \
fi

# Production image, copy all the files and run next
FROM base AS runner
WORKDIR /app

ENV NODE_ENV=production
# Uncomment the following line in case you want to disable telemetry during runtime.
ENV NEXT_TELEMETRY_DISABLED=1

RUN addgroup --system --gid 1001 nodejs
RUN adduser --system --uid 1001 nextjs

COPY --from=builder /app/public ./public

# Automatically leverage output traces to reduce image size
# https://nextjs.org/docs/advanced-features/output-file-tracing
COPY --from=builder --chown=nextjs:nodejs /app/.next/standalone ./
COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static

USER nextjs

EXPOSE 9000

ENV PORT=9000

# server.js is created by next build from the standalone output
# https://nextjs.org/docs/pages/api-reference/config/next-config-js/output
ENV HOSTNAME="0.0.0.0"
CMD ["node", "server.js"]
39 changes: 39 additions & 0 deletions docker-compose.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
services:
traefik:
image: traefik:latest
command:
- --api.insecure=true
- --providers.docker
- --entrypoints.web.address=:80
- --entrypoints.websecure.address=:443
- --certificatesresolvers.letsencrypt.acme.tlschallenge=true
- --certificatesresolvers.letsencrypt.acme.email=${TRAEFIK_EMAIL}
- --certificatesresolvers.letsencrypt.acme.storage=/letsencrypt/acme.json
ports:
- '80:80'
- '443:443'
- '8080:8080'
volumes:
- '/var/run/docker.sock:/var/run/docker.sock'
- './letsencrypt:/letsencrypt'
labels:
- 'traefik.enable=true'
- 'traefik.http.middlewares.redirect-to-nonwww.redirectregex.regex=^https?://www\\.(.+)$$'
- 'traefik.http.middlewares.redirect-to-nonwww.redirectregex.replacement=https://$$1'
- 'traefik.http.middlewares.redirect-to-nonwww.redirectregex.permanent=true'
- 'traefik.http.middlewares.gzip.compress=true'
- 'traefik.http.routers.api.rule=Host(`traefik.${TRAEFIK_DOMAIN}`)'
- 'traefik.http.routers.api.service=api@internal'
- 'traefik.http.routers.api.middlewares=auth'
- 'traefik.http.middlewares.auth.basicauth.users=${TRAEFIK_USER}:${TRAEFIK_PASSWORD}'

reddit-viewer:
build: .
labels:
- 'traefik.enable=true'
- 'traefik.http.routers.reddit-viewer.rule=Host(`${TRAEFIK_DOMAIN}`) || Host(`www.${TRAEFIK_DOMAIN}`)'
- 'traefik.http.routers.reddit-viewer.entrypoints=websecure'
- 'traefik.http.routers.reddit-viewer.middlewares=redirect-to-nonwww,gzip'
- 'traefik.http.routers.reddit-viewer.tls.certresolver=letsencrypt'
depends_on:
- traefik
1 change: 1 addition & 0 deletions next.config.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import type {NextConfig} from 'next'

const nextConfig: NextConfig = {
output: 'standalone',
logging: {
fetches: {
fullUrl: true
Expand Down

0 comments on commit 93e56d3

Please sign in to comment.