-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
51 lines (44 loc) · 2.39 KB
/
Copy pathDockerfile
File metadata and controls
51 lines (44 loc) · 2.39 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
# syntax=docker/dockerfile:1
#
# codeindex distribution image — a thin wrapper around the already-built,
# zero-runtime-dependency bundle. `pnpm build` produces scripts/engine.mjs +
# scripts/engine.d.mts (tsup + postbuild) and both are committed to the repo,
# so there is nothing to `npm install` or compile here: the image is just
# `node`, Git, that bundle, its thin CLI entry, and the optional tree-sitter
# grammars that turn on the AST extraction tier. No src/, no node_modules, no
# embedding model (those are opt-in and stay outside the image — see the
# semantic tier in README.md / `codeindex embed pull`).
#
# Node plus Git: repository metadata and the churn/coupling/delta commands use
# the Git executable even though the JavaScript bundle has no npm dependencies.
# Trust only the documented bind mount: its host UID may differ from node.
# Keep recommended packages out and remove apt metadata after installation.
FROM node:22-slim
RUN apt-get update \
&& apt-get install -y --no-install-recommends git \
&& rm -rf /var/lib/apt/lists/*
RUN git config --system --add safe.directory /work
ARG VERSION=dev
LABEL org.opencontainers.image.source="https://github.com/maxgfr/codeindex" \
org.opencontainers.image.description="Self-contained, deterministic repo-indexing engine (zero runtime deps): walk, symbols, typed link-graph, SCIP index, MCP server." \
org.opencontainers.image.licenses="MIT" \
org.opencontainers.image.version="${VERSION}"
WORKDIR /app
# Bundle + thin CLI entry.
COPY --chown=node:node scripts/engine.mjs scripts/engine.d.mts scripts/cli.mjs ./scripts/
# AST tier: tree-sitter grammars must sit next to engine.mjs (scripts/grammars)
# for the loader's same-directory resolution to find them — see
# resolveGrammarDir() in engine.mjs.
COPY --chown=node:node scripts/grammars ./scripts/grammars
# README.md carries the browser guide, the semantic tier and the versioning
# rules that used to live under docs/ — one file, so the image documents itself
# without a directory to keep in sync.
COPY --chown=node:node package.json README.md LICENSE ./
# Drop root: the image only ever reads its own files and the bind-mounted
# repo under /work, never writes inside /app.
USER node
# The repo to index is bind-mounted here at run time:
# docker run --rm -v $PWD:/work ghcr.io/maxgfr/codeindex scan --repo /work
WORKDIR /work
ENTRYPOINT ["node", "/app/scripts/cli.mjs"]
CMD ["--help"]