# Multi-stage build for Next.js application # Stage 1: Build stage FROM node:20-alpine AS builder WORKDIR /app # NEXT_PUBLIC_* vars are inlined at build time — must be passed as build args ARG NEXT_PUBLIC_SITE_URL ENV NEXT_PUBLIC_SITE_URL=$NEXT_PUBLIC_SITE_URL # Copy package files COPY package.json package-lock.json* ./ # Install dependencies RUN npm ci --prefer-offline --no-audit # Copy source code COPY . . # Build the application RUN npm run build # Stage 2: Production runtime FROM node:20-alpine AS runner WORKDIR /app # Set production environment ENV NODE_ENV=production # Next standalone otherwise inherits Docker's container-ID HOSTNAME and only binds # to the container IP. Bind explicitly to all interfaces for port publishing and healthchecks. ENV HOSTNAME=0.0.0.0 # Create non-root user for security RUN addgroup --system --gid 1001 nodejs RUN adduser --system --uid 1001 nextjs # Copy built application from builder stage COPY --from=builder /app/.next/standalone ./ COPY --from=builder /app/.next/static ./.next/static COPY --from=builder /app/public ./public # Change ownership to non-root user RUN chown -R nextjs:nodejs /app USER nextjs # Expose port EXPOSE 3000 # Health check HEALTHCHECK --interval=30s --timeout=5s --retries=5 \ CMD wget -qO- http://127.0.0.1:3000/api/health || exit 1 # Start the application CMD ["node", "server.js"]