From 630c79d2aa7546d82c96c05483553a2f681d7b66 Mon Sep 17 00:00:00 2001 From: Nick Muerdter <12112+GUI@users.noreply.github.com> Date: Wed, 30 Sep 2026 10:29:53 -0600 Subject: [PATCH] Update docker build and development environment. - Switch Docker images to use docker.io versions to avoid GitHub Actions rate limits with the ECR ones. This was causing builds and deploys to sporadically fail when the rate limits were encountered. - Update base image from NodeJS v20 to v24 and Debian Bookworm to Trixie. - Update pnpm and simplify Docker volume setup to avoid symlinks, since this now works okay with docker volume mounts in development. - Update dart sass and hugo. Holding back on newer versions of Hugo until some issues with pnpm and other issues become more settled. - Bump GitHub Action dependency versions. --- .github/workflows/main.yml | 6 +- Dockerfile | 29 +++---- bin/docker-entrypoint | 20 ----- config.yaml | 9 +-- docker-compose.ci.yml | 2 + docker-compose.yml | 4 +- package.json | 3 +- pnpm-lock.yaml | 158 +++++++++++++++++++++++++++++++++++++ 8 files changed, 179 insertions(+), 52 deletions(-) delete mode 100755 bin/docker-entrypoint diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index a3336a10..fdd2b3e7 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -25,7 +25,7 @@ jobs: prefix=test-image- - name: Login to GitHub Container Registry - uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -71,7 +71,7 @@ jobs: submodules: recursive - name: Login to GitHub Container Registry - uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1 + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -100,7 +100,7 @@ jobs: needs: build runs-on: ubuntu-latest container: - image: rclone/rclone:1.62.2 + image: docker.io/rclone/rclone:1.75.1 strategy: matrix: deploy_env: [production, staging] diff --git a/Dockerfile b/Dockerfile index aba59eea..cc242942 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,22 +1,21 @@ -FROM public.ecr.aws/docker/library/node:20-bookworm-slim +FROM docker.io/library/node:24-trixie-slim ARG TARGETARCH ENV \ DOCKER=true \ NODE_OPTIONS=--use-openssl-ca \ - NODE_MODULES_DIR=/usr/local/node_modules \ PNPM_HOME=/usr/local/pnpm RUN apt-get update && \ apt-get -y --no-install-recommends install curl ca-certificates && \ rm -rf /var/lib/apt/lists/* /var/lib/dpkg/*-old /var/cache/* /var/log/* -ARG HUGO_VERSION=0.159.1 +ARG HUGO_VERSION=0.160.1 RUN set -x && \ curl -fsSL "https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_extended_${HUGO_VERSION}_linux-${TARGETARCH}.tar.gz" | tar -xvz -C /usr/local/bin/ --wildcards "hugo" -ARG DART_SASS_VERSION=1.98.0 +ARG DART_SASS_VERSION=1.105.1 RUN set -x && \ arch="$TARGETARCH" && \ if [ "$TARGETARCH" = "amd64" ]; then \ @@ -24,27 +23,18 @@ RUN set -x && \ fi && \ curl -fsSL "https://github.com/sass/dart-sass/releases/download/${DART_SASS_VERSION}/dart-sass-${DART_SASS_VERSION}-linux-${arch}.tar.gz" | tar -xvz --strip-components 1 -C /usr/local/bin/ --wildcards "*/sass" --wildcards "*/src/*" -# Install pnpm -# -# Set store-dir for pnpm config due to PNPM_HOME not affecting things with some -# of our development volume mounts: https://github.com/pnpm/pnpm/issues/7050 -ARG PNPM_VERSION=10.33.0 +# Configure pnpm. RUN set -x && \ - npm install -g "@pnpm/exe@${PNPM_VERSION}" && \ + corepack enable && \ mkdir -p ~/.config/pnpm && \ - printf "update-notifier=false\nstore-dir=${PNPM_HOME}/store\n" > ~/.config/pnpm/rc + printf "updateNotifier: false\nstoreDir: ${PNPM_HOME}/store\n" > ~/.config/pnpm/config.yaml RUN mkdir -p /app WORKDIR /app -# Symlink the local node_modules to the system-wide node directory. -# -# Note, we create a `.pnpm` directory inside, since it seems to sidestep this issue of -# install failing if node_modules is a symlink: -# https://github.com/pnpm/pnpm/issues/7690 -COPY package.json pnpm-lock.yaml /app/ -RUN mkdir -p "${NODE_MODULES_DIR}/.pnpm" && \ - ln -s "$NODE_MODULES_DIR" /app/node_modules && \ +# Install NPM dependencies. +COPY package.json pnpm-lock.yaml pnpm-workspace.yaml /app/ +RUN --mount=type=cache,target=/usr/local/pnpm/store \ pnpm install COPY .prettierignore .prettierrc.yml config.yaml eslint.config.js postcss.config.js /app/ @@ -54,5 +44,4 @@ COPY content /app/content COPY layouts /app/layouts COPY vendor/datagov-11ty/styles /app/vendor/datagov-11ty/styles -ENTRYPOINT ["/app/bin/docker-entrypoint", "--"] CMD ["/app/bin/docker-start"] diff --git a/bin/docker-entrypoint b/bin/docker-entrypoint deleted file mode 100755 index 33c7fce6..00000000 --- a/bin/docker-entrypoint +++ /dev/null @@ -1,20 +0,0 @@ -#!/usr/bin/env bash - -set -Eeuo pipefail - -app_root_dir="/app" - -# Symlink the node_modules to the expected location for better Docker caching -# when /app is mounted for development/test purposes. -if [ ! -L "${app_root_dir}/node_modules" ] || [ "$(readlink "${app_root_dir}/node_modules")" != "$NODE_MODULES_DIR" ]; then - # Note, we create a `.pnpm` directory inside, since it seems to sidestep this - # issue of install failing if node_modules is a symlink: - # https://github.com/pnpm/pnpm/issues/7690 - mkdir -p "${NODE_MODULES_DIR}/.pnpm" - set -x - rm -rf "${app_root_dir}/node_modules" - ln -s "$NODE_MODULES_DIR" "${app_root_dir}/node_modules" - { set +x; } 2>/dev/null -fi - -exec "$@" diff --git a/config.yaml b/config.yaml index c406fcf4..6461c940 100644 --- a/config.yaml +++ b/config.yaml @@ -1,5 +1,5 @@ baseURL: / -languageCode: en-us +locale: en-us title: api.data.gov disableKinds: - RSS @@ -116,8 +116,5 @@ module: target: static/node_modules/@uswds/uswds/dist/js/ disable404: true security: - exec: - # Add HOME to allowed environment variables list for compatibility with - # asdf-nodejs for postcss. - osEnv: - - "(?i)^(PATH|PATHEXT|APPDATA|TMP|TEMP|TERM|HOME)$" + allowContent: + - ".*" diff --git a/docker-compose.ci.yml b/docker-compose.ci.yml index 2c2adf68..52ff7b9f 100644 --- a/docker-compose.ci.yml +++ b/docker-compose.ci.yml @@ -15,3 +15,5 @@ services: CI: true volumes: - .:/app + # Copy installed modules from built image. + - /app/node_modules/ diff --git a/docker-compose.yml b/docker-compose.yml index 00e47e83..4e41e2d7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -4,11 +4,11 @@ services: context: . volumes: - .:/app + - node_modules_cache:/app/node_modules - pnpm_cache:/usr/local/pnpm - - npm_cache:/usr/local/node_modules ports: - "4490:4490" - "4491:4491" volumes: + node_modules_cache: pnpm_cache: - npm_cache: diff --git a/package.json b/package.json index f1b61514..e6a015c8 100644 --- a/package.json +++ b/package.json @@ -38,5 +38,6 @@ "prettier": "^3.9.6", "prettier-plugin-go-template": "^0.0.15", "vue-eslint-parser": "^10.4.1" - } + }, + "packageManager": "pnpm@12.8.2+sha512.a5941679663d952c5f0ecc38ba98af98b4dc01b95780354f6894f2f873973cef2f7e2989d7db3ee5393938ae21f62fe06bcdf685d475ddad829a62095d2b8b11" } diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index db8321fb..2a26ed42 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -1,3 +1,161 @@ +--- +lockfileVersion: '9.0' + +importers: + + .: + configDependencies: {} + packageManagerDependencies: + pnpm: + specifier: 12.8.2 + version: 12.8.2 + +packages: + + '@pnpm/exe.android-arm64@12.8.2': + resolution: {integrity: sha512-b0gzsJQuxYCX1Pokkf9z+lvajgb5bqBExjmw4kj8H4Bwd2AfH8TkQVxDtrHGptEdkuwokEUSERdpNbRok2cc6Q==} + cpu: [arm64] + os: [android] + + '@pnpm/exe.android-x64@12.8.2': + resolution: {integrity: sha512-j7dzfFMc0XxwhbFvslb06r51tdIlaQQpHUcIrpM7b4ACRYr+LgrpQIB7fI8SdlqPLvsFrrzNYIZXLQN6Kc+xbQ==} + cpu: [x64] + os: [android] + + '@pnpm/exe.darwin-arm64@12.8.2': + resolution: {integrity: sha512-J3cmPRwOVXnPspYeQ3OwwrR8Di9GWRA1aBWD/T1go/4KiD5dvwmE1Q0nW7+F2vAz7FRDRt/91/ZaAujdLX8PIA==} + cpu: [arm64] + os: [darwin] + + '@pnpm/exe.darwin-x64@12.8.2': + resolution: {integrity: sha512-+6UGMD/E7CfzYPqePOkVtWSpDeP7YV5L2k2IwDJykYZ4HH17aYUNGH1FHJSiBTZ/GjLAtdxy0X625sj/wm0w8w==} + cpu: [x64] + os: [darwin] + + '@pnpm/exe.freebsd-x64@12.8.2': + resolution: {integrity: sha512-5fg6lDYuxaPSZawglnhtZMUJI+tgJxybI1DbrKDpQ1v6jitEOptzyMIsrisKVg1sWwO9lbIW+OnQC7OC29ZbOA==} + cpu: [x64] + os: [freebsd] + + '@pnpm/exe.linux-arm64-musl@12.8.2': + resolution: {integrity: sha512-HLOlwfubM+29gs++BDUFejTb09E9aN+4EVzOANU1V9BtoUpY0itBKXeLcxUVTtWwtfAdTUJwmgK6sNgZHC8xBg==} + cpu: [arm64] + os: [linux] + libc: [musl] + + '@pnpm/exe.linux-arm64@12.8.2': + resolution: {integrity: sha512-Q7wIusa83KRHg8MV4hbZq1Ua8pgiET2hJc6U49cd1BWxqob3lwiPg90WLZ5qqYvXM4yytLUSxsMTQlsTWjgsrA==} + cpu: [arm64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-ppc64@12.8.2': + resolution: {integrity: sha512-QQhbXz7q/YK/xkTarU4wv4++aZjVOTZ8BrgLopuJkGdFNtJHJWeXA8cm/SLXir4KTb+pMyc/+Ece44pobEMbkA==} + cpu: [ppc64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-riscv64@12.8.2': + resolution: {integrity: sha512-gfoFW48o3SHMM6hsTKYwobtGKzMR8y+8A9fuXcc0YMdJubR3BmCtzyUa98IWcxM+kE0mKwQYvzxjeaAVppX7qA==} + cpu: [riscv64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-s390x@12.8.2': + resolution: {integrity: sha512-O786sSXtm9Qs5BiUQMKaOGU9n7/UwGzYSTAP2+ltaNMeOTrJSkl9QszOMzlK31/JfTnV4F5dg9PQN2pWdW4aOQ==} + cpu: [s390x] + os: [linux] + libc: [glibc] + + '@pnpm/exe.linux-x64-musl@12.8.2': + resolution: {integrity: sha512-GJ9ZkN9RVlu1LGRYTFjp7c/QAbSYaaVzplP00m4ijKdiv+fGeINeIETBR5MdUZ8biPZf7MJFoKHhMnz88JIj5A==} + cpu: [x64] + os: [linux] + libc: [musl] + + '@pnpm/exe.linux-x64@12.8.2': + resolution: {integrity: sha512-2rjP1HbpSMeSyfbP2CcGG0L2+r+9gHKAjYCZZQj/3SdQBywugJ9aa5OWyPp6yz0Z5xd7tKdUtQJh09TnZOUhwA==} + cpu: [x64] + os: [linux] + libc: [glibc] + + '@pnpm/exe.win32-arm64@12.8.2': + resolution: {integrity: sha512-B1bszoDtTn4o6VGHAE/wrcjceW0zUsxIakTguK3vgbZZ4t6oCv+0d100gJzjmynxg9mHmBXH35JT87SGzyXE2g==} + cpu: [arm64] + os: [win32] + + '@pnpm/exe.win32-x64@12.8.2': + resolution: {integrity: sha512-rOZPUUTU1PHop5dsBQcdQZCnRp7Nz5/v0fnRJkL/4kgKPRONwzD809YwQ/s4mBdSgRY5CcGaYrzwOerp+pFbRg==} + cpu: [x64] + os: [win32] + + pnpm@12.8.2: + resolution: {integrity: sha512-pZQWeWY9lSxfDsw4upivmLTcAblXgDVPaJTy+HOXPO8vfimJ19s+5Tk5OK4h9i/ga832hdR13a2CmmIJXSuLEQ==} + engines: {node: '>=18.*'} + hasBin: true + +snapshots: + + '@pnpm/exe.android-arm64@12.8.2': + optional: true + + '@pnpm/exe.android-x64@12.8.2': + optional: true + + '@pnpm/exe.darwin-arm64@12.8.2': + optional: true + + '@pnpm/exe.darwin-x64@12.8.2': + optional: true + + '@pnpm/exe.freebsd-x64@12.8.2': + optional: true + + '@pnpm/exe.linux-arm64-musl@12.8.2': + optional: true + + '@pnpm/exe.linux-arm64@12.8.2': + optional: true + + '@pnpm/exe.linux-ppc64@12.8.2': + optional: true + + '@pnpm/exe.linux-riscv64@12.8.2': + optional: true + + '@pnpm/exe.linux-s390x@12.8.2': + optional: true + + '@pnpm/exe.linux-x64-musl@12.8.2': + optional: true + + '@pnpm/exe.linux-x64@12.8.2': + optional: true + + '@pnpm/exe.win32-arm64@12.8.2': + optional: true + + '@pnpm/exe.win32-x64@12.8.2': + optional: true + + pnpm@12.8.2: + optionalDependencies: + '@pnpm/exe.android-arm64': 12.8.2 + '@pnpm/exe.android-x64': 12.8.2 + '@pnpm/exe.darwin-arm64': 12.8.2 + '@pnpm/exe.darwin-x64': 12.8.2 + '@pnpm/exe.freebsd-x64': 12.8.2 + '@pnpm/exe.linux-arm64': 12.8.2 + '@pnpm/exe.linux-arm64-musl': 12.8.2 + '@pnpm/exe.linux-ppc64': 12.8.2 + '@pnpm/exe.linux-riscv64': 12.8.2 + '@pnpm/exe.linux-s390x': 12.8.2 + '@pnpm/exe.linux-x64': 12.8.2 + '@pnpm/exe.linux-x64-musl': 12.8.2 + '@pnpm/exe.win32-arm64': 12.8.2 + '@pnpm/exe.win32-x64': 12.8.2 + +--- lockfileVersion: '9.0' settings: