Add deployment: Dockerfile, compose, proxy config, and docs

One container plus a Postgres behind any TLS-terminating proxy. Nothing is
specific to a particular host.

The app and API are served from a SINGLE origin. This is not tidiness: browser
auth sessions live in per-origin storage, so splitting them across two
hostnames makes sign-in loop in a way that presents as a server fault. The
short alias redirects rather than serving a second origin.

Two safety properties verified by running the image, not by reading the code:

- With NODE_ENV=production and no SUPABASE_URL, the process refuses to start
  and says why. Serving the whole CRM unauthenticated is a worse outcome than
  failing to deploy, so the failure is deliberate and loud.
- In production the development auth bypass does not apply: an unauthenticated
  request to /api/dashboard returns 401 rather than adopting the first user in
  the table.

The Dockerfile typechecks all six packages as a build gate, so a deploy that
does not compile fails at build time rather than in front of a user. Runtime
runs unprivileged as `node`, and Postgres is not published to the host.

Docs cover the ontology and why it is shaped this way, agent connection for
Claude Code / Codex / prime-agent / Buzz, and the provenance rules governing
seed data about real people — including how to have your record removed.

Verified: image builds, container reports healthy, serves the SPA, enforces
auth, and the production guard exits non-zero.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-12 19:19:53 -07:00
parent de33a03524
commit c747eb2aa7
7 changed files with 456 additions and 0 deletions
+67
View File
@@ -0,0 +1,67 @@
# PIG — production image.
#
# Multi-stage so the runtime image carries no build toolchain and no source
# maps. The front end is built into the API's static directory and served from
# the same origin, which matters for more than tidiness: auth sessions are
# per-origin, so splitting the app across two hostnames turns sign-in into a
# redirect loop that looks like a broken deployment.
FROM node:22-alpine AS build
WORKDIR /app
# Manifests first, so a dependency install is cached across source-only edits.
COPY package.json package-lock.json* ./
COPY packages/core/package.json packages/core/
COPY packages/db/package.json packages/db/
COPY packages/prime/package.json packages/prime/
COPY apps/api/package.json apps/api/
COPY apps/web/package.json apps/web/
COPY apps/mcp/package.json apps/mcp/
RUN npm install --no-audit --no-fund
COPY . .
# Typecheck as a build gate. A deploy that does not compile should fail here,
# loudly, rather than at runtime in front of a user.
RUN npx tsc --noEmit -p packages/core/tsconfig.json \
&& npx tsc --noEmit -p packages/db/tsconfig.json \
&& npx tsc --noEmit -p packages/prime/tsconfig.json \
&& npx tsc --noEmit -p apps/api/tsconfig.json \
&& npx tsc --noEmit -p apps/web/tsconfig.json \
&& npx tsc --noEmit -p apps/mcp/tsconfig.json
RUN npm run build -w @pig/web
# ---------------------------------------------------------------- runtime
FROM node:22-alpine AS runtime
WORKDIR /app
ENV NODE_ENV=production
# Reinstall without dev dependencies. tsx is needed at runtime because the
# server runs TypeScript directly; everything else is production-only.
COPY package.json package-lock.json* ./
COPY packages/core/package.json packages/core/
COPY packages/db/package.json packages/db/
COPY packages/prime/package.json packages/prime/
COPY apps/api/package.json apps/api/
COPY apps/mcp/package.json apps/mcp/
RUN npm install --omit=dev --no-audit --no-fund && npm install tsx --no-audit --no-fund
COPY packages ./packages
COPY apps/api ./apps/api
COPY apps/mcp ./apps/mcp
COPY --from=build /app/apps/web/dist ./apps/web/dist
# Run unprivileged. The node image ships a `node` user for exactly this.
RUN chown -R node:node /app
USER node
EXPOSE 8920
# The health endpoint is unauthenticated by design so this works without
# credentials baked into the image.
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
CMD node -e "fetch('http://127.0.0.1:8920/api/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"
CMD ["npx", "tsx", "apps/api/src/server.ts"]