Monorepo (pnpm workspaces) with two deployable apps and three pure packages. apps/api (Hono on Node): Zod validated env that fails fast and names the problem, Kysely factories for SQLite and Postgres chosen by DATABASE_URL scheme, portable migrations covering the whole SPEC section 5 schema, Better Auth with the four roles and seeded demo accounts, localized error envelope, /healthz and /readyz, graceful SIGTERM drain. Dialect specific SQL is confined to the two factories. apps/web (Next.js App Router): locale routed shell in es and en with a language switcher, sign in screen, and a runtime /api proxy so the browser only ever sees one origin and cookies stay first party. packages/i18n ships both catalogs complete; es is generated from COPY.md and a test re-derives it from the document on every run so it cannot drift. packages/contracts holds the Zod schemas and the typed client the web app uses. Verified: 43 vitest tests, 14 Playwright tests on mobile and desktop, typecheck and lint clean, migrate and seed from a clean database, sign in through the proxy with CSRF rejection of foreign origins. Not verified here: docker compose. This user has no access to the docker socket. RULES.md is absent from docs/, so packages/rules exports only RULES_VERSION and no tax rule, check digit or deadline was invented. See DECISIONS.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
41 lines
1.4 KiB
Docker
41 lines
1.4 KiB
Docker
# syntax=docker/dockerfile:1
|
|
|
|
# Build stage: the whole workspace is needed because apps/api imports the packages/*
|
|
# source directly and tsup bundles it in.
|
|
FROM node:22-slim AS build
|
|
ENV PNPM_HOME=/pnpm PATH=/pnpm:$PATH
|
|
RUN corepack enable
|
|
WORKDIR /repo
|
|
|
|
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml tsconfig.base.json ./
|
|
COPY apps/api/package.json apps/api/
|
|
COPY apps/web/package.json apps/web/
|
|
COPY packages/contracts/package.json packages/contracts/
|
|
COPY packages/i18n/package.json packages/i18n/
|
|
COPY packages/rules/package.json packages/rules/
|
|
RUN --mount=type=cache,id=pnpm,target=/pnpm/store pnpm install --frozen-lockfile
|
|
|
|
COPY packages packages
|
|
COPY apps/api apps/api
|
|
COPY docs docs
|
|
RUN pnpm --filter @impuestos/api build
|
|
RUN pnpm --filter @impuestos/api deploy --prod --legacy /prod/api
|
|
|
|
FROM node:22-slim AS runtime
|
|
ENV NODE_ENV=production
|
|
WORKDIR /app
|
|
|
|
# Owns ./data, the SQLite file and the local storage driver's files.
|
|
RUN mkdir -p /app/data && chown -R node:node /app
|
|
|
|
COPY --from=build --chown=node:node /prod/api/node_modules ./node_modules
|
|
COPY --from=build --chown=node:node /repo/apps/api/dist ./dist
|
|
COPY --from=build --chown=node:node /repo/apps/api/package.json ./package.json
|
|
|
|
USER node
|
|
EXPOSE 4000
|
|
|
|
# SIGTERM is handled in src/index.ts: fail readiness, drain, close the pool, exit 0.
|
|
# No init shim, so node stays PID 1 and receives the signal directly.
|
|
CMD ["node", "dist/index.js"]
|