mirror of
https://github.com/penpot/penpot.git
synced 2026-10-03 09:16:15 +00:00
* 🐛 Migrate openUIApi schema to Zod v4 function syntax Zod 4 removed z.function().args(), which broke the plugins-runtime build with implicit-any errors on every openUIApi parameter and knock-on possibly-null errors on the modal in plugin-manager. Declare the inputs with z.function({ input: [...] }) so the parameter and return types infer again; behavior is unchanged. Add a regression spec covering delegation, optional args and rejection of invalid theme and title values. AI-assisted-by: muse-spark-1.3-contributor * 📚 Fix deprecated markdown-it-anchor permalink option in docs Migrate docs Eleventy config to the markdown-it-anchor v10 API. Replace the deprecated boolean permalink option with linkInsideHeader, keeping the same symbol and class. Bump markdown-it-anchor to v10 and related docs deps. AI-assisted-by: muse-spark-1.3-contributor * ⬆️ Update deps * ⬆️ Update base docker images * 📎 Fix mcp tests
54 lines
2.3 KiB
Docker
54 lines
2.3 KiB
Docker
FROM dhi.io/nginx:1.31.6-debian13-dev
|
|
LABEL maintainer="Penpot <docker@penpot.app>"
|
|
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
|
|
USER root
|
|
|
|
RUN set -ex; \
|
|
apt-get -qq update; \
|
|
apt-get -qq -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" dist-upgrade; \
|
|
apt-get -qqy -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" --no-install-recommends install bash gettext-base passwd; \
|
|
rm -rf /var/lib/apt/lists/*; \
|
|
groupadd -f -g 1001 penpot; \
|
|
useradd -M -u 1001 -s /usr/sbin/nologin -d /opt/penpot -g penpot penpot; \
|
|
mkdir -p /opt/data/assets; \
|
|
chown -R penpot:penpot /opt/data; \
|
|
mkdir -p /etc/nginx/overrides/main.d/; \
|
|
mkdir -p /etc/nginx/overrides/http.d/; \
|
|
mkdir -p /etc/nginx/overrides/server.d/; \
|
|
mkdir -p /etc/nginx/overrides/assets.d/; \
|
|
mkdir -p /etc/nginx/overrides/location.d/;
|
|
|
|
ARG BUNDLE_PATH="./bundle-frontend/"
|
|
COPY $BUNDLE_PATH /var/www/app/
|
|
COPY ./files/config.js /var/www/app/js/config.js
|
|
COPY ./files/nginx.conf.template /tmp/nginx.conf.template
|
|
COPY ./files/nginx-resolvers.conf.template /tmp/resolvers.conf.template
|
|
COPY ./files/nginx-admin-console-locations.conf.template /tmp/nginx-admin-console-locations.conf.template
|
|
COPY ./files/nginx-mcp-locations.conf.template /tmp/nginx-mcp-locations.conf.template
|
|
COPY ./files/nginx-security-headers.conf.template /tmp/nginx-security-headers.conf.template
|
|
COPY ./files/nginx-mime.types /etc/nginx/mime.types
|
|
COPY ./files/nginx-external-locations.conf /etc/nginx/overrides/location.d/external-locations.conf
|
|
COPY ./files/nginx-entrypoint.sh /entrypoint.sh
|
|
|
|
# The CSP hashes of the inline scripts of index.html are emitted by the
|
|
# frontend build. Move them out of the document root: nginx must read them,
|
|
# the browser has no reason to.
|
|
RUN if [ -f /var/www/app/csp-script-hashes.txt ]; then \
|
|
mv /var/www/app/csp-script-hashes.txt /etc/nginx/csp-script-hashes.txt; \
|
|
else \
|
|
echo "WARNING: the frontend bundle does not provide csp-script-hashes.txt" >&2; \
|
|
fi
|
|
|
|
RUN chown -R 1001:0 /var/cache/nginx; \
|
|
chmod -R g+w /var/cache/nginx; \
|
|
chown -R 1001:0 /etc/nginx; \
|
|
chmod -R g+w /etc/nginx; \
|
|
chown -R 1001:0 /var/www; \
|
|
chmod -R g+w /var/www;
|
|
|
|
USER penpot:penpot
|
|
ENTRYPOINT ["/bin/bash", "/entrypoint.sh"]
|
|
CMD ["nginx", "-g", "daemon off;"]
|