docker: digest-pin the node:22-bookworm-slim build base

Pin the floating node:22-bookworm-slim tag to its index digest. The re-resolve
of this unpinned docker.io tag every build was the recurring CI 'hang'. Paired
with the bastion runner now pulling through the zot mirror, the base is fetched
once and cached. (nginx runtime stage was already digest-pinned.)
This commit is contained in:
2026-06-23 20:47:02 +10:00
parent c5d9da9092
commit dc42d31595
+4 -1
View File
@@ -3,7 +3,10 @@
# pinned nginx-unprivileged runtime serving the static dist/. # pinned nginx-unprivileged runtime serving the static dist/.
# ---- build stage ---------------------------------------------------------- # ---- build stage ----------------------------------------------------------
FROM node:22-bookworm-slim AS build # Digest-pinned (was a floating tag → the docker.io re-resolve was the CI "build hang"). With the bastion
# runner pointed at the zot pull-through mirror, this exact layer is fetched once and cached. Bump the digest
# when intentionally moving Node. node:22-bookworm-slim index digest resolved 2026-06-23.
FROM node:22-bookworm-slim@sha256:d9f850096136edbc402debdd8729579a288aac64574ada0ff4db26b6ae58b0b2 AS build
WORKDIR /app WORKDIR /app
# Install deps from the lockfile only first (better layer caching). # Install deps from the lockfile only first (better layer caching).