mirror of
https://github.com/simstudioai/sim.git
synced 2026-09-24 15:45:35 +08:00
* feat(secrets): ingest env secrets at container runtime instead of fanning into ECS taskdef The app/socket ECS taskdefs were ~42KB, ~93% of which was the secrets[] array: 268 pointer entries each restating the full ~78-char secret ARN, marching toward the 64KB taskdef limit and growing ~150 bytes per hosted key added. The secret blob itself is only ~18KB/268 keys. Move secret delivery to container boot: new @sim/runtime-secrets loadRuntimeSecrets() reads SIM_ENV_SECRET_ID, fetches the combined secret once, and hydrates process.env (no-clobber, no-op when unset, fail-fast). Bootstrap entrypoints for app + realtime await it before importing the real server (env-flags reads env at module load). The app bootstrap is bun-bundled in the Dockerfile builder stage since it runs outside the Next standalone bundle; realtime keeps full node_modules and runs the TS entry. Backward-compatible: with the current fan-out taskdef the loader no-ops and the app reads the injected env vars unchanged. The matching infra change (empty secrets[] + SIM_ENV_SECRET_ID) ships separately, after this image is live. * fix(runtime-secrets): address review feedback - Move the binary-secret guard outside the retry loop (sendWithRetry) so a missing SecretString throws immediately instead of burning 3 attempts + backoff. - Bound each Secrets Manager request with AbortSignal.timeout(5s) so a stalled response can't hang boot indefinitely. - Drop the redundant @aws-sdk/client-secrets-manager pin from apps/realtime; it resolves transitively via @sim/runtime-secrets. - Add a test for the non-retriable binary-secret path.
53 lines
1.3 KiB
Docker
53 lines
1.3 KiB
Docker
# ========================================
|
|
# Base Stage: Alpine Linux with Bun
|
|
# ========================================
|
|
FROM oven/bun:1.3.13-alpine AS base
|
|
|
|
RUN apk add --no-cache libc6-compat curl
|
|
|
|
# ========================================
|
|
# Pruner Stage: Emit a minimal monorepo subset that @sim/realtime depends on
|
|
# ========================================
|
|
FROM base AS pruner
|
|
WORKDIR /app
|
|
|
|
RUN bun add -g turbo
|
|
|
|
COPY . .
|
|
|
|
RUN turbo prune @sim/realtime --docker
|
|
|
|
# ========================================
|
|
# Dependencies Stage: Install Dependencies
|
|
# ========================================
|
|
FROM base AS deps
|
|
WORKDIR /app
|
|
|
|
COPY --from=pruner /app/out/json/ ./
|
|
COPY --from=pruner /app/out/bun.lock ./bun.lock
|
|
|
|
RUN --mount=type=cache,id=bun-cache,target=/root/.bun/install/cache \
|
|
bun install --linker=hoisted --omit=dev --ignore-scripts
|
|
|
|
# ========================================
|
|
# Runner Stage: Run the Socket Server
|
|
# ========================================
|
|
FROM base AS runner
|
|
WORKDIR /app
|
|
|
|
ENV NODE_ENV=production \
|
|
PORT=3002 \
|
|
HOSTNAME="0.0.0.0"
|
|
|
|
RUN addgroup -g 1001 -S nodejs && \
|
|
adduser -S nextjs -u 1001
|
|
|
|
COPY --from=deps --chown=nextjs:nodejs /app ./
|
|
COPY --from=pruner --chown=nextjs:nodejs /app/out/full/ ./
|
|
|
|
USER nextjs
|
|
|
|
EXPOSE 3002
|
|
|
|
CMD ["bun", "apps/realtime/src/bootstrap.ts"]
|