# This file is based on these images: # # - https://hub.docker.com/r/hexpm/elixir/tags - for the builder image # E.g.: docker.io/hexpm/elixir:1.20.2-erlang-29.0.3-debian-trixie-20260713-slim # - https://hub.docker.com/_/debian/tags?name=trixie-20260713-slim - for the runner image # E.g.: docker.io/debian:trixie-20260713-slim # # Find builder and runner images on Docker Hub or on Hex's Build Server (Bob). # We recommend using Bob's Web UI to find recent tags: # # - https://bob.hex.pm/docker # # We suggest using the same Debian version for both the builder and runner images. # # We suggest Debian/Ubuntu instead of Alpine to avoid production compatibility issues # (such as DNS resolution failures, and dynamically linked NIFs/precompiled binaries). # # For finding packages in Debian, search on https://packages.debian.org/. ARG ELIXIR_VERSION=1.20.2 ARG OTP_VERSION=29.0.3 ARG DEBIAN_VERSION=trixie-20260713-slim ARG BUILDER_IMAGE="docker.io/hexpm/elixir:${ELIXIR_VERSION}-erlang-${OTP_VERSION}-debian-${DEBIAN_VERSION}@sha256:6fcd8ea864221b960c1ec418e3b10fa488298ff9e70c9e0f3db18070e610fb8a" ARG RUNNER_IMAGE="docker.io/debian:${DEBIAN_VERSION}@sha256:020c0d20b9880058cbe785a9db107156c3c75c2ac944a6aa7ab59f2add76a7bd" FROM docker.io/node:24.18.0-bookworm-slim@sha256:6f7b03f7c2c8e2e784dcf9295400527b9b1270fd37b7e9a7285cf83b6951452d AS node_deps WORKDIR /assets COPY assets/package.json assets/package-lock.json ./ RUN npm install --global npm@12.0.1 \ && npm ci FROM ${BUILDER_IMAGE} AS builder # install build dependencies RUN apt-get update \ && apt-get install -y --no-install-recommends \ build-essential=12.12 \ git=1:2.47.3-0+deb13u1 \ && rm -rf /var/lib/apt/lists/* # prepare build dir WORKDIR /app # install hex + rebar RUN mix local.hex --force \ && mix local.rebar --force # set build ENV ENV MIX_ENV="prod" # install mix dependencies COPY mix.exs mix.lock ./ RUN mix deps.get --only $MIX_ENV RUN mkdir config ARG WNH_E2E_ROUTES=false ENV WNH_E2E_ROUTES="${WNH_E2E_ROUTES}" # copy compile-time config files before we compile dependencies # to ensure any relevant config change will trigger the dependencies # to be re-compiled. COPY config/config.exs config/${MIX_ENV}.exs config/ RUN mix deps.compile RUN mix assets.setup COPY priv priv COPY lib lib # Compile the release RUN mix compile COPY assets assets COPY --from=node_deps /assets/node_modules assets/node_modules # compile assets RUN mix assets.deploy # Changes to config/runtime.exs don't require recompiling the code COPY config/runtime.exs config/ COPY rel rel RUN mix release # start a new build stage so that the final image will only contain # the compiled release and other runtime necessities FROM ${RUNNER_IMAGE} AS final RUN apt-get update \ && apt-get install -y --no-install-recommends \ ca-certificates=20250419 \ curl=8.14.1-2+deb13u4 \ iproute2=6.15.0-1 \ libncurses6=6.5+20250216-2 \ libsctp1=1.0.21+dfsg-1 \ libstdc++6=14.2.0-19 \ locales=2.41-12+deb13u3 \ openssl=3.5.6-1~deb13u2 \ && rm -rf /var/lib/apt/lists/* # Set the locale RUN sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen \ && locale-gen ENV LANG=en_US.UTF-8 ENV LANGUAGE=en_US:en ENV LC_ALL=en_US.UTF-8 WORKDIR "/app" RUN chown nobody /app # set runner ENV ENV MIX_ENV="prod" # Only copy the final release from the build stage COPY --from=builder --chown=nobody:root /app/_build/${MIX_ENV}/rel/who_need_help ./ USER nobody # If using an environment that doesn't automatically reap zombie processes, it is # advised to add an init process such as tini via `apt-get install` # above and adding an entrypoint. See https://github.com/krallin/tini for details # ENTRYPOINT ["/tini", "--"] CMD ["/app/bin/server"] FROM ${BUILDER_IMAGE} AS test RUN apt-get update \ && apt-get install -y --no-install-recommends \ build-essential=12.12 \ ca-certificates=20250419 \ git=1:2.47.3-0+deb13u1 \ && rm -rf /var/lib/apt/lists/* WORKDIR /app RUN mix local.hex --force \ && mix local.rebar --force ENV MIX_ENV="test" COPY mix.exs mix.lock ./ RUN mix deps.get --only test COPY config config RUN mix deps.compile COPY .dialyzer_ignore.exs .formatter.exs ./ COPY priv priv COPY lib lib COPY test test RUN mix compile CMD ["mix", "test"] FROM test AS quality # PLTs are expensive to create but deterministic for the pinned Erlang, # Elixir, dependency lock, and test environment. Cache them in this dedicated # target so every quality command uses the same analyzed dependency set. RUN mix dialyzer --plt CMD ["mix", "dialyzer"] FROM builder AS load_tools CMD ["mix", "wnh.load_fixtures"] # Keep the production release as the default build result while exposing the # dedicated `test`, `quality`, and isolated `load_tools` targets to local # verification scripts. FROM final AS release