Adds apps/podsteadr (main Fastify+Vue app, container.build from the podsteadr repo), apps/podsteadr-mediamtx (RTMP/WHIP ingest, HLS, recording), and apps/podsteadr-blossom (BUD-02 media blobs), wired together on a dedicated podsteadr-net bridge network per the multi-container pattern documented in docs/app-developer-guide.md (indeedhub's api/relay/minio/redis/postgres siblings). All podsteadr ports are auth: none with a rationale, since it's a public podcast/livestream server whose RSS feeds, HLS playback, and blob reads must stay reachable by third-party clients with no Archipelago session — the app already gates its own sensitive routes with NIP-98 and per-stream secret keys. Also updates apps/PORTS.md, apps/README.md, and bumps the reviewed unauthenticated-port count in core/container/src/manifest.rs's unauthenticated_ports_are_all_accounted_for test (25 -> 31) to acknowledge the six new auth:none ports. Regenerated catalog-derived files (core/archipelago/src/fips/app_ports.rs, neode-ui/src/views/appSession/generatedAppSessionConfig.ts) via scripts/generate-app-catalog.py. All three manifests pass scripts/validate-app-manifest.sh and `cargo test -p archipelago-container manifest`.
45 lines
1.5 KiB
Docker
45 lines
1.5 KiB
Docker
# Vendored copy of the podsteadr repo's own Dockerfile (source lives outside
|
|
# this tree — http://146.59.87.168:3000/ssmithx/podsteadr). Re-sync by hand if
|
|
# the upstream Dockerfile changes; build with build-from-prototype.sh, which
|
|
# passes the podsteadr repo root as build context (this Dockerfile expects
|
|
# frontend/ and server/ subdirectories at the context root, not this apps/
|
|
# directory).
|
|
#
|
|
# ---- frontend ----
|
|
FROM node:22-bookworm-slim AS frontend-build
|
|
WORKDIR /build/frontend
|
|
COPY frontend/package*.json ./
|
|
RUN npm ci
|
|
COPY frontend/ ./
|
|
RUN npm run build
|
|
|
|
# ---- server ----
|
|
FROM node:22-bookworm-slim AS server-build
|
|
WORKDIR /build/server
|
|
COPY server/package*.json ./
|
|
RUN npm ci
|
|
COPY server/ ./
|
|
RUN npm run build && npm prune --omit=dev
|
|
|
|
# ---- runtime ----
|
|
FROM node:22-bookworm-slim
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends ffmpeg curl \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
WORKDIR /app
|
|
COPY --from=server-build /build/server/node_modules ./node_modules
|
|
COPY --from=server-build /build/server/package.json ./package.json
|
|
COPY --from=server-build /build/server/dist ./dist
|
|
COPY --from=frontend-build /build/frontend/dist ./public
|
|
# Named volumes inherit ownership from the image path: keep /data writable by node
|
|
RUN mkdir -p /data && chown node:node /data
|
|
USER node
|
|
ENV NODE_ENV=production \
|
|
PORT=8095 \
|
|
DATA_DIR=/data \
|
|
STATIC_DIR=/app/public
|
|
EXPOSE 8095
|
|
HEALTHCHECK --interval=30s --timeout=5s --retries=3 \
|
|
CMD curl -fsS http://localhost:8095/api/health || exit 1
|
|
CMD ["node", "dist/index.js"]
|