chore: add Dockerfile for TanStack Start production build

This commit is contained in:
2026-04-21 23:19:44 +02:00
parent 2590d60e58
commit 58921ca65b
3 changed files with 56 additions and 18 deletions

6
.dockerignore Normal file
View File

@@ -0,0 +1,6 @@
node_modules
.output
.git
.env*
.DS_Store
*.log

View File

@@ -15,22 +15,33 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with: with:
fetch-depth: 0 registry: ghcr.io
- uses: actions/setup-go@v5 username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with: with:
go-version: 1.22 images: ghcr.io/${{ github.repository }}
cache: true tags: |
- uses: ko-build/setup-ko@v0.7 type=semver,pattern={{version}}
- uses: sigstore/cosign-installer@v3.7.0 type=semver,pattern={{major}}.{{minor}}
type=sha
- name: Build and push Docker image
uses: docker/build-push-action@v5
with: with:
cosign-release: v2.2.3 context: .
- uses: goreleaser/goreleaser-action@v5 push: true
with: tags: ${{ steps.meta.outputs.tags }}
version: v1.24.0 labels: ${{ steps.meta.outputs.labels }}
args: release --clean cache-from: type=gha
env: cache-to: type=gha,mode=max
GITHUB_TOKEN: '${{ secrets.GITHUB_TOKEN }}'
COSIGN_PASSWORD: '${{ secrets.COSIGN_PASSWORD }}'
COSIGN_PRIVATE_KEY: '${{ secrets.COSIGN_PRIVATE_KEY }}'
COSIGN_PUBLIC_KEY: '${{ secrets.COSIGN_PUBLIC_KEY }}'

21
Dockerfile Normal file
View File

@@ -0,0 +1,21 @@
# Stage 1 — deps + build
FROM oven/bun:1 AS builder
WORKDIR /app
COPY package.json bun.lock ./
RUN bun install --frozen-lockfile
COPY . .
RUN bun run build
# Stage 2 — production runtime
FROM node:22-alpine AS runner
WORKDIR /app
COPY --from=builder /app/.output ./.output
EXPOSE 3000
ENV NODE_ENV=production
CMD ["node", ".output/server/index.mjs"]