# Build stage FROM node:22-alpine AS build WORKDIR /app # Copy package files and install dependencies COPY package*.json ./ RUN npm ci # Copy source code COPY . . # Build the app RUN npm run build # Production stage FROM node:22-alpine # Create app directory with non-root user WORKDIR /app RUN addgroup -S appgroup && adduser -S appuser -G appgroup && \ chown -R appuser:appgroup /app # Copy built assets from build stage COPY --from=build --chown=appuser:appgroup /app/dist ./dist COPY --from=build --chown=appuser:appgroup /app/node_modules ./node_modules COPY --from=build --chown=appuser:appgroup /app/package.json ./package.json # Security best practices ENV NODE_ENV=production RUN npm prune --production # Set permissions and switch to non-root user USER appuser # Expose port EXPOSE 4000 # Health check endpoint HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \ CMD wget --no-verbose --tries=1 --spider http://localhost:4000/health || exit 1 # Start the application CMD ["npm", "start"]