-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
49 lines (46 loc) · 1.79 KB
/
Copy pathdocker-compose.yml
File metadata and controls
49 lines (46 loc) · 1.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
# Preview and build the site without installing Node or Hugo on the host.
#
# docker compose up serve http://localhost:1313/
# docker compose run --rm build production build into ./public
#
# A bare `git clone` is enough: the entrypoint fetches submodules into the bind
# mount and installs the toolchain on first run.
#
# Note there are deliberately NO named volumes for node_modules. Docker creates a
# volume's mountpoint inside the bind mount as root, which then blocks both the
# submodule checkout and `npm ci` for the unprivileged container user. Letting
# node_modules live in the working tree — written by uid 1000, same as the host
# user — avoids that entirely, and keeps it inspectable from the host.
x-common: &common
build: .
image: agstack/docs:local
# `:z` relabels the bind-mounted tree to container_file_t. Without it, on any
# SELinux-enforcing host (Fedora, RHEL, CentOS), a checkout under $HOME carries
# user_home_t, which container processes may not read — the mount then fails
# with "Permission denied" despite being world-readable. Ignored elsewhere.
volumes:
- .:/src:z
environment:
# The container user may not exist in /etc/passwd when APP_UID is overridden,
# so point HOME and the npm cache somewhere always writable.
HOME: /tmp
NPM_CONFIG_CACHE: /tmp/.npm
# Defaults to the image's `node` user. Override in a .env file if your host
# account is not uid 1000, so files written into the mount stay yours:
# APP_UID=1001
# APP_GID=1001
user: "${APP_UID:-1000}:${APP_GID:-1000}"
services:
serve:
<<: *common
ports:
- "1313:1313"
command: >
npm run hugo -- server
--bind 0.0.0.0
--port 1313
--disableFastRender
build:
<<: *common
profiles: ["cli"]
command: npm run build