From 4e8c6e534bc57af5d2f57d389267e7ce04f05743 Mon Sep 17 00:00:00 2001 From: Thomas Faour Date: Mon, 27 Jul 2026 20:40:30 +0000 Subject: [PATCH] Install Node.js from Debian's own repo, drop NodeSource dependency deb.nodesource.com started intermittently 403ing today on both its setup_*.x scripts and its GPG key (confirmed directly, not just via CI -- some setup_NN.x paths 403, others 200, no consistent pattern), and the curl-piped-into-bash install pattern silently swallowed that failure instead of breaking the build loudly: curl -f exits non-zero on a 403, but bash then runs on empty stdin and exits 0, so the RUN kept going into a broken fallback (Debian's own split nodejs package with no bundled npm) rather than stopping. This base image now tracks Debian trixie, whose own nodejs package (20.19.2) is inside jsdom 29's engines range and clears express/ resvg-js's much lower floors -- the version gap that originally required routing through NodeSource is gone, so this drops that whole external dependency (and the curl/gnupg install-then-purge dance) rather than just swapping to a different NodeSource script. --- server/Dockerfile | 54 +++++++++++++++++++++++++---------------------- 1 file changed, 29 insertions(+), 25 deletions(-) diff --git a/server/Dockerfile b/server/Dockerfile index 20b91eb..2d099a7 100644 --- a/server/Dockerfile +++ b/server/Dockerfile @@ -2,34 +2,38 @@ FROM python:3.12-slim WORKDIR /app -# tzdata/fonts in their own layer, kept separate from the much larger -# Node.js/npm layers below -- see those layers' own comments for why -# they're split up the way they are. tzdata: python:3.12-slim doesn't -# include it by default, so the zoneinfo database backing the web UI's -# "Timezone" setting (used by "Quiet hours") would have no named zones -# to resolve without this -- ZoneInfo() would raise for anything other -# than "UTC". fontconfig/fonts-dejavu-core: whiteboard mode's -# render-service/ (own README there) needs something to render -# whiteboard text with. -RUN apt-get update && apt-get install -y --no-install-recommends \ - tzdata fontconfig fonts-dejavu-core \ - && rm -rf /var/lib/apt/lists/* - +# tzdata/fonts/Node.js all from Debian's own repo in one layer -- no +# external curl/gnupg dance needed (see below for why that changed). +# tzdata: python:3.12-slim doesn't include it by default, so the +# zoneinfo database backing the web UI's "Timezone" setting (used by +# "Quiet hours") would have no named zones to resolve without this -- +# ZoneInfo() would raise for anything other than "UTC". +# fontconfig/fonts-dejavu-core: whiteboard mode's render-service/ (own +# README there) needs something to render whiteboard text with. +# # Node.js: whiteboard frame mode's render-service/ runs as a second # process in this same container rather than a separate compose service # -- it's a lightweight, stateless, localhost-only sidecar with nothing -# worth independently scaling or restarting. NodeSource's setup script is -# used instead of Debian bookworm's own apt Node package, which is both -# older than jsdom's minimum (20.19+) and inconsistently available. -# curl/gnupg are only needed to add and fetch NodeSource's repo -- purged -# again in this same RUN (not a later one; Docker layers are immutable, -# so removing them in a *different* instruction wouldn't shrink this -# one's actual pushed size) so their bytes don't end up in the image at -# all, only nodejs's. -RUN apt-get update && apt-get install -y --no-install-recommends curl ca-certificates gnupg \ - && curl -fsSL https://deb.nodesource.com/setup_22.x | bash - \ - && apt-get install -y --no-install-recommends nodejs \ - && apt-get purge -y --auto-remove curl gnupg \ +# worth independently scaling or restarting. Used to be installed via +# NodeSource's setup script (Debian's own nodejs package was too old for +# jsdom's minimum back when this base image tracked Debian bookworm) -- +# switched to Debian's own `nodejs`/`npm` packages after NodeSource's +# deb.nodesource.com started intermittently 403ing on both its setup_*.x +# scripts *and* its GPG key (a live NodeSource-side S3/CDN issue, +# confirmed 2026-07-27 by hitting deb.nodesource.com directly -- some +# setup_NN.x paths 403, others 200, no consistent pattern, so no +# NodeSource-hosted install path could be trusted not to silently break +# again). This base image now tracks Debian trixie, whose own `nodejs` +# package is 20.19.2 -- inside jsdom 29's stated engines range +# (`^20.19.0 || ^22.13.0 || >=24.0.0`) and well above express/resvg-js's +# much lower floors -- so there's no longer a version gap to route +# around NodeSource for. One less external dependency, and no more +# curl-piped-into-bash (that pattern is also what let the NodeSource +# failure go undetected here in the first place: `curl -f ... | bash -` +# on a 403 hands bash an empty, "successful" script instead of failing +# the RUN outright). +RUN apt-get update && apt-get install -y --no-install-recommends \ + tzdata fontconfig fonts-dejavu-core nodejs npm \ && rm -rf /var/lib/apt/lists/* COPY requirements.txt .