This commit is contained in:
Saufi
2026-06-14 09:17:46 +08:00
parent 359229685d
commit 5ec68d3fe9
10 changed files with 515 additions and 1 deletions

99
docker/Dockerfile Normal file
View File

@@ -0,0 +1,99 @@
# syntax=docker/dockerfile:1
# ---------------------------------------------------------------------------
# Stage 1: build front-end assets with Vite (Node 22 ~ npm 10.9.x)
# ---------------------------------------------------------------------------
FROM node:22-bookworm-slim AS assets
WORKDIR /app
# Install JS deps first for better layer caching. No package-lock.json is
# committed, so use `npm install` rather than `npm ci`.
COPY package.json ./
RUN npm install
# Only the inputs Vite needs to produce public/build
COPY vite.config.js ./
COPY resources ./resources
RUN npm run build
# ---------------------------------------------------------------------------
# Stage 2: PHP 8.4 dependencies + application code (the "app" / php-fpm image)
# ---------------------------------------------------------------------------
FROM php:8.4-fpm-bookworm AS app
# System libraries required to build the PHP extensions below.
RUN apt-get update && apt-get install -y --no-install-recommends \
git \
unzip \
rsync \
libzip-dev \
libpng-dev \
libjpeg-dev \
libfreetype-dev \
libonig-dev \
libicu-dev \
libxml2-dev \
&& docker-php-ext-configure gd --with-freetype --with-jpeg \
&& docker-php-ext-install -j"$(nproc)" \
pdo_mysql \
mbstring \
bcmath \
gd \
zip \
intl \
exif \
pcntl \
opcache \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*
# Composer (pulled from the official image; 2.x line, matches host 2.9.x)
COPY --from=composer:2 /usr/bin/composer /usr/bin/composer
# PHP runtime configuration
COPY docker/php/php.ini /usr/local/etc/php/conf.d/zz-app.ini
WORKDIR /var/www/html
# Install PHP dependencies first (better caching). Skip scripts/autoloader
# until the full source tree is present.
COPY composer.json composer.lock ./
RUN composer install \
--no-dev \
--no-scripts \
--no-autoloader \
--prefer-dist \
--no-interaction \
--no-progress
# Application source + freshly built front-end assets
COPY . .
COPY --from=assets /app/public/build ./public/build
# Optimised autoloader (package discovery runs at container start instead,
# where the environment is available).
RUN composer dump-autoload --no-dev --optimize --no-interaction \
&& chown -R www-data:www-data storage bootstrap/cache \
&& chmod -R ug+rwX storage bootstrap/cache
# Entrypoint prepares storage, caches config, runs migrations, then runs the
# given command (php-fpm by default).
COPY docker/php/entrypoint.sh /usr/local/bin/entrypoint
RUN chmod +x /usr/local/bin/entrypoint
EXPOSE 9000
ENTRYPOINT ["entrypoint"]
CMD ["php-fpm"]
# ---------------------------------------------------------------------------
# Stage 3: nginx serving the static assets + proxying PHP to the app container
# ---------------------------------------------------------------------------
FROM nginx:1.27-alpine AS web
# Baked copy of the public root so nginx can serve static files directly.
COPY --from=app /var/www/html/public /var/www/html/public
COPY docker/nginx/default.conf /etc/nginx/conf.d/default.conf
EXPOSE 80

View File

@@ -0,0 +1,32 @@
# Host nginx reverse proxy for the Dockerized app.
# Install on the Ubuntu host:
# sudo cp docker/host-nginx/taklimatspr.apps.mbip.my.conf \
# /etc/nginx/sites-available/taklimatspr.apps.mbip.my
# sudo ln -s /etc/nginx/sites-available/taklimatspr.apps.mbip.my \
# /etc/nginx/sites-enabled/
# sudo nginx -t && sudo systemctl reload nginx
server {
listen 80;
listen [::]:80;
server_name taklimatspr.apps.mbip.my;
client_max_body_size 21M;
access_log /var/log/nginx/taklimatspr.access.log;
error_log /var/log/nginx/taklimatspr.error.log;
location / {
proxy_pass http://127.0.0.1:8008;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
proxy_connect_timeout 30s;
proxy_read_timeout 60s;
}
}

34
docker/nginx/default.conf Normal file
View File

@@ -0,0 +1,34 @@
server {
listen 80;
server_name _;
root /var/www/html/public;
index index.php;
charset utf-8;
client_max_body_size 21M;
# Real client IP / forwarded headers come from the host nginx in front.
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
error_page 404 /index.php;
# Pass PHP requests to the app (php-fpm) container.
location ~ \.php$ {
fastcgi_pass app:9000;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
include fastcgi_params;
fastcgi_hide_header X-Powered-By;
}
# Deny access to hidden files (e.g. .env) and version control.
location ~ /\.(?!well-known).* {
deny all;
}
}

66
docker/php/entrypoint.sh Normal file
View File

@@ -0,0 +1,66 @@
#!/usr/bin/env bash
set -euo pipefail
cd /var/www/html
echo "[entrypoint] Preparing storage directories..."
mkdir -p \
storage/app/public \
storage/framework/cache/data \
storage/framework/sessions \
storage/framework/views \
storage/framework/testing \
storage/logs \
bootstrap/cache
chown -R www-data:www-data storage bootstrap/cache || true
chmod -R ug+rwX storage bootstrap/cache || true
# Refresh package manifest (env vars are available now via compose env_file).
php artisan package:discover --ansi || true
# Wait for the database to be reachable before migrating / caching config.
wait_for_db() {
local host="${DB_HOST:-127.0.0.1}"
local port="${DB_PORT:-3306}"
echo "[entrypoint] Waiting for database at ${host}:${port}..."
for i in $(seq 1 30); do
if php -r '
$h=getenv("DB_HOST")?:"127.0.0.1";
$p=getenv("DB_PORT")?:"3306";
$d=getenv("DB_DATABASE")?:"";
$u=getenv("DB_USERNAME")?:"root";
$w=getenv("DB_PASSWORD")?:"";
try { new PDO("mysql:host=$h;port=$p;dbname=$d", $u, $w, [PDO::ATTR_TIMEOUT=>2]); exit(0); }
catch (Throwable $e) { exit(1); }
' >/dev/null 2>&1; then
echo "[entrypoint] Database is up."
return 0
fi
sleep 2
done
echo "[entrypoint] WARNING: database not reachable after timeout; continuing anyway."
return 0
}
# Cache framework config for performance. Runs in every role so all containers
# share the same compiled config.
cache_app() {
php artisan config:cache --ansi || true
php artisan route:cache --ansi || true
php artisan view:cache --ansi || true
}
# Only the primary (web/app) container runs migrations & storage:link, so the
# queue/scheduler workers don't race on them. Toggle with RUN_MIGRATIONS.
if [ "${RUN_MIGRATIONS:-true}" = "true" ]; then
wait_for_db
cache_app
echo "[entrypoint] Running migrations..."
php artisan migrate --force --ansi || echo "[entrypoint] WARNING: migrate failed."
php artisan storage:link --ansi || true
else
cache_app
fi
echo "[entrypoint] Starting: $*"
exec "$@"

20
docker/php/php.ini Normal file
View File

@@ -0,0 +1,20 @@
; Application PHP settings (production-leaning)
expose_php = Off
memory_limit = 256M
max_execution_time = 60
; File uploads (attendance app — keep modest but comfortable)
upload_max_filesize = 20M
post_max_size = 21M
; Timezone (app uses Asia/Kuala_Lumpur)
date.timezone = Asia/Kuala_Lumpur
; OPcache — enabled for production performance
opcache.enable = 1
opcache.enable_cli = 0
opcache.memory_consumption = 128
opcache.interned_strings_buffer = 16
opcache.max_accelerated_files = 20000
opcache.validate_timestamps = 1
opcache.revalidate_freq = 60