From 6a28c3b7ba47c2b7a50ec202f6cf6ac0134820e8 Mon Sep 17 00:00:00 2001 From: Giancarmine Salucci Date: Wed, 8 Jul 2026 01:14:16 +0200 Subject: [PATCH] chore(infra): dockerize for software-house outcome gate Co-Authored-By: Claude Fable 5 --- .dockerignore | 26 ++++++++++++++++++++++++++ compose.yaml | 42 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 68 insertions(+) create mode 100644 .dockerignore create mode 100644 compose.yaml diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..e84a7f2 --- /dev/null +++ b/.dockerignore @@ -0,0 +1,26 @@ +node_modules +npm-debug.log* + +.git +.gitea + +# Build outputs (rebuilt fresh in the builder stage; stale copies would shadow it) +.svelte-kit +build +*.tsbuildinfo + +# Docs / editor / misc — not needed in the image +docs +*.md +.vscode +.DS_Store + +# Env files — never bake secrets into the image; compose supplies env at runtime +.env +.env.* +!.env.example + +# Container tooling itself +Dockerfile +compose.yaml +.dockerignore diff --git a/compose.yaml b/compose.yaml new file mode 100644 index 0000000..c3b91df --- /dev/null +++ b/compose.yaml @@ -0,0 +1,42 @@ +# Software-house outcome-gate scaffold. +# +# No `container_name` and no anonymous/random host port: `app`'s host port is a +# stable, project-specific mapping (4173) that will not collide with the gate +# running this stack under a `-p ` prefix alongside a live deployment — +# both instances share the same compose.yaml, isolated by project name, and the +# gate/orchestrator polls this exact port for the health check (toolchain +# health_url must match). +services: + app: + build: + context: . + dockerfile: Dockerfile + ports: + - "4173:3000" + # WHISPER_URL/WEBHOOK_BASE_URL/VAPID_*/OUTPUT_DIR/DATA_DIR all have safe + # in-app defaults (see src/lib/server/*.ts) — override via a .env file or + # `environment:` here for a real deployment; nothing is required to boot. + environment: + NODE_ENV: production + volumes: + # Named volume at $HOME for the `node` user (uid 1000) — the base image + # already owns /home/node, so Docker seeds the volume with that ownership + # on first create. Persists jobs.db + transcripts across restarts. + - tonemark-data:/home/node + healthcheck: + # Node 22 has global fetch (undici) — no curl/wget needed in the runtime image. + test: + [ + "CMD", + "node", + "-e", + "fetch('http://localhost:3000/api/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))" + ] + interval: 10s + timeout: 5s + retries: 10 + start_period: 15s + restart: unless-stopped + +volumes: + tonemark-data: