Pinned 2026 toolchains (Go 1.26, Rust 1.98/edition 2024, Python 3.14 + uv, Node 24, Zig 0.16, NixOS 26.05), postgres 18 / mongo 8, lockfiles built from, non-root runtimes, .dockerignore, per-project LICENSE, READMEs with the git.devai.io clone line, checkout@v7 CI. Security fixes in the legacy Rust APIs (any-password login, self-assigned admin, hard-coded JWT secret), JWT alg/exp/sub enforcement across the blog series, safe markdown links in the frontends, and many smaller bugs — every project was built, run and exercised end to end. Adds scripts/publish.sh + a CI publish job that splits every folder into its own repo at git.devai.io/templates/<folder>. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01128fhuZbgivaSJvtMf4s1G
14 lines
566 B
Docker
14 lines
566 B
Docker
FROM dart:3.13 AS build
|
|
WORKDIR /app
|
|
COPY pubspec.yaml pubspec.lock ./
|
|
RUN dart pub get --enforce-lockfile
|
|
COPY . .
|
|
RUN dart compile js -O2 -o build/main.dart.js web/main.dart
|
|
|
|
FROM nginxinc/nginx-unprivileged:1.30-alpine
|
|
# The image's entrypoint runs envsubst on templates/*.template, so API_URL is read at start-up.
|
|
COPY nginx.conf.template /etc/nginx/templates/default.conf.template
|
|
COPY web/index.html web/styles.css /usr/share/nginx/html/
|
|
COPY --from=build /app/build/main.dart.js /usr/share/nginx/html/
|
|
ENV API_URL=http://host.docker.internal:8080
|
|
EXPOSE 8080
|