# syntax=docker/dockerfile:1 # # Next.js Dockerfile for passenger web (portal + backoffice). # Builds with turbo, runs with Node.js (not nginx). # # Build example (portal): # DOCKER_BUILDKIT=1 docker build \ # --build-arg APP_PACKAGE=@edr/passenger-portal \ # --build-arg APP_PATH=apps/edr-passenger-web/portal \ # --build-arg PORT=5174 \ # -f infrastructure/docker/Dockerfile.passenger-web . # ARG APP_PACKAGE=@edr/passenger-portal ARG APP_PATH=apps/edr-passenger-web/portal ARG PORT=5174 ARG NEXT_PUBLIC_API_URL FROM node:24.15.0-alpine AS base RUN apk add --no-cache libc6-compat # Store pnpm's content-addressable store under PNPM_HOME so the BuildKit # `--mount=type=cache,target=/pnpm/store` cache actually persists deps across builds. ENV PNPM_HOME="/pnpm" ENV PATH="$PNPM_HOME:$PATH" RUN corepack enable WORKDIR /app FROM base AS pruner ARG APP_PACKAGE COPY . . RUN pnpm dlx turbo prune "${APP_PACKAGE}" --docker FROM base AS installer COPY --from=pruner /app/out/json/ . COPY --from=pruner /app/out/pnpm-lock.yaml ./pnpm-lock.yaml RUN --mount=type=secret,id=npmrc,target=./.npmrc,required=false \ --mount=type=cache,id=pnpm,target=/pnpm/store \ pnpm install --frozen-lockfile FROM base AS builder ARG APP_PACKAGE ARG APP_PATH ARG NEXT_PUBLIC_API_URL ENV NEXT_PUBLIC_API_URL=${NEXT_PUBLIC_API_URL} RUN if [ -z "$NEXT_PUBLIC_API_URL" ]; then \ echo "ERROR: NEXT_PUBLIC_API_URL must be set" && \ exit 1; \ fi COPY --from=installer /app/ . COPY --from=pruner /app/out/full/ . RUN pnpm turbo build --filter="${APP_PACKAGE}..." FROM base AS deployer ARG APP_PACKAGE COPY --from=builder /app/ . RUN --mount=type=cache,id=pnpm,target=/pnpm/store \ pnpm deploy --filter="${APP_PACKAGE}" --prod --legacy /deploy FROM node:24.15.0-alpine AS runner ARG APP_PATH ARG PORT=5174 ENV PORT=${PORT} ENV NODE_ENV=production WORKDIR /app COPY --from=deployer /deploy . COPY --from=builder /app/${APP_PATH}/.next .next COPY --from=builder /app/${APP_PATH}/public public USER node EXPOSE ${PORT} CMD ["npx", "next", "start"]