diff --git a/server/Dockerfile b/server/Dockerfile index 20b91eb..2d099a7 100644 --- a/server/Dockerfile +++ b/server/Dockerfile @@ -2,34 +2,38 @@ FROM python:3.12-slim WORKDIR /app -# tzdata/fonts in their own layer, kept separate from the much larger -# Node.js/npm layers below -- see those layers' own comments for why -# they're split up the way they are. tzdata: python:3.12-slim doesn't -# include it by default, so the zoneinfo database backing the web UI's -# "Timezone" setting (used by "Quiet hours") would have no named zones -# to resolve without this -- ZoneInfo() would raise for anything other -# than "UTC". fontconfig/fonts-dejavu-core: whiteboard mode's -# render-service/ (own README there) needs something to render -# whiteboard text with. -RUN apt-get update && apt-get install -y --no-install-recommends \ - tzdata fontconfig fonts-dejavu-core \ - && rm -rf /var/lib/apt/lists/* - +# tzdata/fonts/Node.js all from Debian's own repo in one layer -- no +# external curl/gnupg dance needed (see below for why that changed). +# tzdata: python:3.12-slim doesn't include it by default, so the +# zoneinfo database backing the web UI's "Timezone" setting (used by +# "Quiet hours") would have no named zones to resolve without this -- +# ZoneInfo() would raise for anything other than "UTC". +# fontconfig/fonts-dejavu-core: whiteboard mode's render-service/ (own +# README there) needs something to render whiteboard text with. +# # Node.js: whiteboard frame mode's render-service/ runs as a second # process in this same container rather than a separate compose service # -- it's a lightweight, stateless, localhost-only sidecar with nothing -# worth independently scaling or restarting. NodeSource's setup script is -# used instead of Debian bookworm's own apt Node package, which is both -# older than jsdom's minimum (20.19+) and inconsistently available. -# curl/gnupg are only needed to add and fetch NodeSource's repo -- purged -# again in this same RUN (not a later one; Docker layers are immutable, -# so removing them in a *different* instruction wouldn't shrink this -# one's actual pushed size) so their bytes don't end up in the image at -# all, only nodejs's. -RUN apt-get update && apt-get install -y --no-install-recommends curl ca-certificates gnupg \ - && curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \ - && apt-get install -y --no-install-recommends nodejs \ - && apt-get purge -y --auto-remove curl gnupg \ +# worth independently scaling or restarting. Used to be installed via +# NodeSource's setup script (Debian's own nodejs package was too old for +# jsdom's minimum back when this base image tracked Debian bookworm) -- +# switched to Debian's own `nodejs`/`npm` packages after NodeSource's +# deb.nodesource.com started intermittently 403ing on both its setup_*.x +# scripts *and* its GPG key (a live NodeSource-side S3/CDN issue, +# confirmed 2026-07-27 by hitting deb.nodesource.com directly -- some +# setup_NN.x paths 403, others 200, no consistent pattern, so no +# NodeSource-hosted install path could be trusted not to silently break +# again). This base image now tracks Debian trixie, whose own `nodejs` +# package is 20.19.2 -- inside jsdom 29's stated engines range +# (`^20.19.0 || ^22.13.0 || >=24.0.0`) and well above express/resvg-js's +# much lower floors -- so there's no longer a version gap to route +# around NodeSource for. One less external dependency, and no more +# curl-piped-into-bash (that pattern is also what let the NodeSource +# failure go undetected here in the first place: `curl -f ... | bash -` +# on a 403 hands bash an empty, "successful" script instead of failing +# the RUN outright). +RUN apt-get update && apt-get install -y --no-install-recommends \ + tzdata fontconfig fonts-dejavu-core nodejs npm \ && rm -rf /var/lib/apt/lists/* COPY requirements.txt .