Files
iot-dc3/Dockerfile
T
pnoker ef2995c9b4 chore(nginx): adopt http2 directive and lift limit_req_zone to http scope
Upstream nginx 1.25 deprecated the "listen ... http2" parameter in
favour of a standalone "http2 on;" directive, and 1.27 emits a config
warning on the old form. Switch the default server to the new shape so
the dc3-web image stays clean on the pinned 1.27 base.

limit_req_zone is only valid in the http context — declaring it inside
the server block silently shadowed the rate-limit configuration on
reload. Move it up to nginx.conf:http so the api zone is actually
registered, while leaving limit_req_status in the server block where
the limit is consumed.

Dockerfile envsubst now whitelists ${APP_API_HOST} and ${APP_API_PORT}
so unrelated $-prefixed nginx variables in default.env aren't rewritten
to empty strings at container start.
2026-05-14 23:44:06 +08:00

47 lines
1.4 KiB
Docker

#
# Copyright 2016-present the IoT DC3 original author or authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
# builder
FROM pnoker/dc3-node:2025.2 AS builder
LABEL dc3.author=pnokers
LABEL dc3.author.email=pnokers.icloud.com
RUN ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime
WORKDIR /build
COPY ./ ./
RUN corepack enable && corepack prepare pnpm@10.33.2 --activate
RUN pnpm install --frozen-lockfile
RUN pnpm build
# runtime
FROM pnoker/dc3-nginx:2025.2 AS runtime
LABEL dc3.author=pnokers
LABEL dc3.author.email=pnokers.icloud.com
RUN ln -sf /usr/share/zoneinfo/Asia/Shanghai /etc/localtime
COPY --from=builder /build/dc3/nginx/ /etc/nginx/
COPY --from=builder /build/dist/ /usr/share/nginx/html/
COPY --from=builder /build/dc3/dependencies/conf.crt/ /etc/letsencrypt/live/
EXPOSE 80 443
VOLUME /var/log/nginx
CMD envsubst '${APP_API_HOST} ${APP_API_PORT}' < /etc/nginx/location/default.env > /etc/nginx/location/default.conf ; nginx -g "daemon off;"