# One small image runs the whole game: a zero-dependency Node server that # serves the static frontend and lists the installed themes/languages. FROM node:24-alpine ENV NODE_ENV=production \ PORT=8080 WORKDIR /app # Files stay owned by root and read-only for the runtime user: the app can't modify itself. COPY package.json ./ COPY server ./server COPY public ./public # Run as the unprivileged "node" user (uid 1000) that ships with the image. USER node EXPOSE 8080 HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ CMD ["node", "-e", "fetch('http://127.0.0.1:' + process.env.PORT + '/healthz').then(r => process.exit(r.ok ? 0 : 1), () => process.exit(1))"] CMD ["node", "server/index.js"]