From 6e93e24df013c63067ee82eea61ad9c541cbee62 Mon Sep 17 00:00:00 2001 From: Lucas Berger Date: Thu, 18 Jun 2026 21:19:45 -0400 Subject: [PATCH] chore(260618-tg2): BuildKit pnpm-store cache mount in Dockerfile build Add 'RUN --mount=type=cache,target=/pnpm-store' to all 3 pnpm install stages (builder/pwa-builder/production) with --store-dir /pnpm-store, plus the '# syntax=docker/dockerfile:1' directive. Set DOCKER_BUILDKIT=1 on the publish build step so the legacy builder can't break on the mount syntax. sharing=locked because builder and pwa-builder run in parallel. Co-Authored-By: Claude Opus 4.8 (1M context) --- .gitea/workflows/publish.yml | 5 +++++ apps/api/Dockerfile | 10 +++++++--- 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/.gitea/workflows/publish.yml b/.gitea/workflows/publish.yml index fcc2bad..c27c999 100644 --- a/.gitea/workflows/publish.yml +++ b/.gitea/workflows/publish.yml @@ -88,6 +88,11 @@ jobs: # Build from REPO ROOT (T-08-10): the Dockerfile copies the pnpm workspace manifest + # lockfile from the root context; building from apps/api/ would fail to find them. - name: Build production image + # DOCKER_BUILDKIT=1 is required: the Dockerfile uses `RUN --mount=type=cache` + # (BuildKit) to persist the pnpm store across builds. The legacy builder would + # fail on that syntax. BuildKit is default on Docker 23+, set explicitly for safety. + env: + DOCKER_BUILDKIT: '1' run: | set -euo pipefail docker build --target production \ diff --git a/apps/api/Dockerfile b/apps/api/Dockerfile index 09418ff..117ca98 100644 --- a/apps/api/Dockerfile +++ b/apps/api/Dockerfile @@ -1,3 +1,4 @@ +# syntax=docker/dockerfile:1 # Built from the REPO ROOT context (see docker-compose.yml: build.context: .) # so the pnpm workspace manifest + lockfile are available for a deterministic, # workspace-aware install. apps/api is one package in the pnpm workspace. @@ -12,7 +13,8 @@ FROM base AS builder COPY pnpm-workspace.yaml pnpm-lock.yaml package.json ./ COPY apps/api/package.json ./apps/api/ COPY apps/pwa/package.json ./apps/pwa/ -RUN pnpm install --frozen-lockfile --filter @familysync/api... +RUN --mount=type=cache,target=/pnpm-store,id=pnpm-store,sharing=locked \ + pnpm install --frozen-lockfile --filter @familysync/api... --store-dir /pnpm-store COPY apps/api ./apps/api RUN pnpm --filter @familysync/api build @@ -28,7 +30,8 @@ FROM base AS pwa-builder COPY pnpm-workspace.yaml pnpm-lock.yaml package.json ./ COPY apps/api/package.json ./apps/api/ COPY apps/pwa/package.json ./apps/pwa/ -RUN pnpm install --frozen-lockfile --filter @familysync/pwa... +RUN --mount=type=cache,target=/pnpm-store,id=pnpm-store,sharing=locked \ + pnpm install --frozen-lockfile --filter @familysync/pwa... --store-dir /pnpm-store COPY apps/pwa ./apps/pwa RUN pnpm --filter @familysync/pwa build @@ -36,7 +39,8 @@ FROM base AS production COPY pnpm-workspace.yaml pnpm-lock.yaml package.json ./ COPY apps/api/package.json ./apps/api/ COPY apps/pwa/package.json ./apps/pwa/ -RUN pnpm install --frozen-lockfile --prod --filter @familysync/api... +RUN --mount=type=cache,target=/pnpm-store,id=pnpm-store,sharing=locked \ + pnpm install --frozen-lockfile --prod --filter @familysync/api... --store-dir /pnpm-store COPY --from=builder /app/apps/api/dist ./apps/api/dist WORKDIR /app/apps/api # Enforce production identity — engages the NODE_ENV=production hard guard