Production-Only Files

Copying Only What Production Needs

The runtime stage starts from a clean node:24-slim and takes node_modules from deps, three files and the two directories the API reads. An explicit list instead of COPY . . means a file added to the repository later, such as a fixture with test credentials, never reaches production by accident:

The runtime image holds only what the API loadsShell
for t in 1.1 1.1-test; do docker run --rm l3-booknest-api:$t ls /app | xargs echo "$t:"; done
Output
1.1: app.js db node_modules package.json public server.js
1.1-test: app.js db node_modules package-lock.json package.json public server.js test

Whatever else npm 2,036 ci created stays behind with the discarded stage, so RUN and Caching's && npm cache clean trick is no longer needed. For a native add-on, compile in FROM node:24 AS deps and run in FROM node:24-slim; keep both on the same C library (never compile on Alpine 13,255 's musl and run on Debian 319 's glibc).