mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 11:49:16 +00:00
4f26f22cce
* feat: add license gating system with Lemon Squeezy integration Add Community/Pro tier infrastructure: - LicenseService singleton with Lemon Squeezy license API integration - /api/license endpoints (GET info, POST activate/deactivate/validate) - 14-day Pro trial activated automatically on first boot - 72-hour periodic validation with 30-day offline grace period - LicenseContext provider for frontend tier awareness - License settings tab with activation UI and status display - ProBadge and ProGate reusable components for feature gating - requirePro per-route guard for backend Pro-only endpoints - Proxy bypass for /api/license routes (local-only, never proxied) * feat: add user profile dropdown and reorganize top navigation - Create UserProfileDropdown component with settings, billing, theme toggle (System/Light/Dark), documentation links, and logout button - Remove logout button from sidebar header - Remove standalone settings button from top bar - Move theme toggle from Settings modal to profile dropdown - Inject app version via Vite define from root package.json - Add globals.d.ts for __APP_VERSION__ type declaration * refactor(settings): remove appearance tab from settings modal Theme toggle was moved to the User Profile Dropdown in the previous commit. Remove the now-redundant Appearance section, its nav button, and the unused theme/setTheme props from SettingsModal. * feat: add fleet view dashboard and about settings section Fleet Overview: aggregates all nodes into a card grid showing status, container counts, CPU/RAM/disk usage bars. Pro tier unlocks stack drill-down with auto-refresh (30s). Backend endpoints /api/fleet/overview and /api/fleet/node/:nodeId/stacks query nodes in parallel. About section in Settings: displays version, license tier, status, instance ID, and links to docs/changelog/issues. Sidebar perf fix: stack status fetches now run in parallel via Promise.allSettled instead of sequential for-loop, significantly reducing load time for nodes with many stacks. Also removes version number from User Profile Dropdown (now in About). * fix(ci): resolve Docker build and E2E test failures - Copy root package.json into frontend build stage so vite.config.ts can read the app version during Docker multi-stage build. - Update auth E2E test: logout button moved into User Profile Dropdown. - Update nodes E2E test: Settings button moved into User Profile Dropdown.
146 lines
5.7 KiB
Docker
146 lines
5.7 KiB
Docker
# Cross-compilation helper — provides xx-clang, xx-apk, etc.
|
|
# Runs on the BUILD platform; its binaries are copied into build stages below.
|
|
FROM --platform=$BUILDPLATFORM tonistiigi/xx AS xx
|
|
|
|
# Stage 1: Build Frontend
|
|
# Runs on the BUILD platform (amd64) — frontend has no native modules so the
|
|
# compiled output (JS/CSS/HTML) is entirely platform-agnostic.
|
|
FROM --platform=$BUILDPLATFORM node:20-alpine AS frontend-builder
|
|
|
|
WORKDIR /app/frontend
|
|
|
|
COPY frontend/package*.json frontend/.npmrc ./
|
|
RUN npm config set fetch-retry-maxtimeout 120000 && \
|
|
npm config set fetch-retries 5 && \
|
|
npm install
|
|
|
|
COPY frontend/ ./
|
|
# vite.config.ts reads the root package.json for the app version
|
|
COPY package.json /app/package.json
|
|
RUN npm run build
|
|
|
|
# Stage 2: Compile TypeScript
|
|
# Runs on the BUILD platform (amd64) — tsc output is platform-agnostic JS.
|
|
FROM --platform=$BUILDPLATFORM node:20-alpine AS backend-builder
|
|
|
|
WORKDIR /app/backend
|
|
|
|
RUN apk add --no-cache python3 make g++
|
|
|
|
COPY backend/package*.json backend/.npmrc ./
|
|
RUN npm config set fetch-retry-maxtimeout 120000 && \
|
|
npm config set fetch-retries 5 && \
|
|
npm install
|
|
|
|
COPY backend/ ./
|
|
RUN npm run build
|
|
|
|
# Stage 3: Production dependencies (cross-compiled — NO QEMU execution)
|
|
# Runs on the BUILD platform (amd64) but compiles native modules
|
|
# (bcrypt, better-sqlite3, node-pty) for the TARGET platform using
|
|
# tonistiigi/xx + clang as the cross-compiler.
|
|
# This avoids the Node.js v20 SIGILL crash that occurs when npm runs
|
|
# under QEMU because QEMU lacks ARMv8.1 LSE atomic instruction support.
|
|
FROM --platform=$BUILDPLATFORM node:20-alpine AS prod-deps
|
|
|
|
# Copy xx cross-compilation tools into this stage
|
|
COPY --from=xx / /
|
|
|
|
ARG TARGETARCH
|
|
ARG BUILDARCH
|
|
|
|
WORKDIR /app
|
|
|
|
# Two paths depending on whether we are cross-compiling:
|
|
#
|
|
# Native (TARGETARCH == BUILDARCH, e.g. amd64 → amd64):
|
|
# Standard g++ is used. xx-clang introduces sysroot flags that conflict with
|
|
# node-gyp's header resolution on Alpine for same-platform builds, so we
|
|
# bypass it entirely and let npm ci use the host compiler directly.
|
|
#
|
|
# Cross (TARGETARCH != BUILDARCH, e.g. amd64 → arm64):
|
|
# xx-clang targets the foreign architecture without QEMU. The target sysroot
|
|
# is populated via xx-apk:
|
|
# g++ — libstdc++ headers/libs (all three native modules use C++)
|
|
# musl-dev — musl libc headers for the target arch
|
|
# linux-headers — <pty.h> / <termios.h> required by node-pty
|
|
RUN if [ "$TARGETARCH" = "$BUILDARCH" ]; then \
|
|
apk add --no-cache python3 make g++; \
|
|
else \
|
|
apk add --no-cache clang lld python3 make g++ && \
|
|
xx-apk add --no-cache g++ musl-dev linux-headers; \
|
|
fi
|
|
|
|
COPY backend/package*.json backend/.npmrc ./
|
|
|
|
# Native: plain npm ci — g++ compiles native modules for the host arch.
|
|
# Cross: npm_config_arch tells prebuild-install/node-pre-gyp which pre-built
|
|
# binary to attempt; CC/CXX/AR route compilation through xx-clang so
|
|
# the output targets the foreign arch without any QEMU emulation.
|
|
RUN if [ "$TARGETARCH" = "$BUILDARCH" ]; then \
|
|
npm ci --omit=dev; \
|
|
else \
|
|
npm_config_arch=$TARGETARCH \
|
|
CC=xx-clang \
|
|
CXX=xx-clang++ \
|
|
AR=xx-ar \
|
|
npm ci --omit=dev; \
|
|
fi
|
|
|
|
# Stage 4: Production runtime
|
|
# Runs on the TARGET platform — no compilation happens here.
|
|
FROM node:20-alpine
|
|
|
|
# Install Docker CLI, Docker Compose CLI, and Bash for Host Console
|
|
RUN apk add --no-cache docker-cli docker-cli-compose bash su-exec
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy cross-compiled production node_modules from the prod-deps stage
|
|
COPY --from=prod-deps /app/node_modules ./node_modules
|
|
COPY --from=prod-deps /app/package.json ./
|
|
|
|
# Copy compiled TypeScript output (platform-agnostic JS)
|
|
COPY --from=backend-builder /app/backend/dist ./dist
|
|
|
|
# Copy built frontend
|
|
COPY --from=frontend-builder /app/frontend/dist ./public
|
|
|
|
# Set environment to production
|
|
ENV NODE_ENV=production
|
|
|
|
# Create a non-root user and ensure the data/compose directories are writable.
|
|
# The actual volume paths are mounted at runtime, so we only pre-create the
|
|
# default data dir here; the compose dir is user-supplied via COMPOSE_DIR.
|
|
RUN addgroup -S sencho && adduser -S -G sencho sencho \
|
|
&& mkdir -p /app/data \
|
|
&& chown -R sencho:sencho /app
|
|
|
|
# Copy the entrypoint script that fixes data-volume ownership at startup and
|
|
# then drops privileges to the sencho user via su-exec (the idiomatic Alpine
|
|
# equivalent of gosu). This mirrors the pattern used by official Docker images
|
|
# such as PostgreSQL, Redis, and MariaDB.
|
|
#
|
|
# NOTE: USER directive is intentionally absent here. The entrypoint starts as
|
|
# root so it can chown the mounted data volume, then exec's as sencho. Static
|
|
# security scanners (Trivy, Clair) may flag "running as root" — this is a known
|
|
# and accepted trade-off for self-hosted apps with user-supplied volume mounts.
|
|
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
|
# Strip Windows CRLF line endings that can sneak in on Windows dev machines
|
|
# even with .gitattributes eol=lf, then make executable. A shell script with
|
|
# \r in tokens like "fi\r" will fail with "unexpected end of file" in Alpine.
|
|
RUN sed -i 's/\r//' /usr/local/bin/docker-entrypoint.sh \
|
|
&& chmod +x /usr/local/bin/docker-entrypoint.sh
|
|
|
|
# Expose port
|
|
EXPOSE 3000
|
|
|
|
# Health check — polls the public /api/health endpoint every 30s
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
|
|
CMD node -e "const h=require('http');h.get('http://localhost:3000/api/health',r=>{process.exit(r.statusCode===200?0:1)}).on('error',()=>process.exit(1))"
|
|
|
|
# Entrypoint fixes volume ownership as root then drops to sencho via su-exec.
|
|
# CMD provides the default arguments passed through to the entrypoint.
|
|
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
|
|
CMD ["node", "dist/index.js"]
|