repositories / will
will
owned by admin
Containerfile.service
Raw# syntax=docker/dockerfile:1
# will-service: unprivileged, read-only-rootfs phenotype container.
# Base is a digest-pinned Arch runtime (deliberately rebuilt via mise; see mise.toml).
ARG SERVICE_BASE=ghcr.io/bugabinga/will-service-base:latest
FROM ${SERVICE_BASE}
# Bundled service + worker + static frontend/docs; no node_modules (zero runtime deps).
COPY dist/service.js dist/service-worker.js /app/
COPY web/dist/ /app/web-dist/
COPY docs/dist/ /app/docs-dist/
USER will-service
EXPOSE 3000
ENV NODE_ENV=production
HEALTHCHECK --interval=10s --timeout=3s --start-period=30s --retries=3 \
CMD node -e "fetch('http://127.0.0.1:3000/healthz').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"
ENTRYPOINT ["node", "/app/service.js"]