Planning Images

Planning BookNest's Container Images

BookNest runs as three containers: the API (which also serves the front end) from this section's Dockerfile, an Nginx 75 front end added in Nginx Front End, and the official postgres:18. Which base? node:24-slim (Choosing a Base Image). What goes in? Production dependencies and source; never the host's node_modules, .git or secrets. How is it configured? Only through environment variables, which BookNest already reads (PORT and the PG* variables). Who runs it? An unprivileged user. How does Docker 514 know it works? A healthcheck against /health, which never touches the database. The result, saved as Dockerfile in the project root:

Dockerfile: BookNest's API imageDockerfile
# syntax=docker/dockerfile:1
# BookNest API: Node.js 24 + Express 5, talks to PostgreSQL through PG* variables.
FROM node:24-slim
ARG NODE_ENV=production
ENV NODE_ENV=${NODE_ENV} \
    PORT=3000
WORKDIR /app
# Dependencies first: this layer is rebuilt only when the manifests change.
COPY package.json package-lock.json ./
RUN npm ci --omit=dev && npm cache clean --force
# Application code, owned by root and read-only for the runtime user.
COPY . .
# The image's unprivileged "node" user, by number so Kubernetes can verify it is not root.
USER 1000:1000
EXPOSE 3000
HEALTHCHECK --interval=30s --timeout=3s --start-period=10s --retries=3 \
  CMD ["node", "-e", \
  "fetch('http://127.0.0.1:3000/health').then(r=>process.exit(r.ok?0:1),()=>process.exit(1))"]
CMD ["node", "server.js"]

The first line is a parser directive telling BuildKit 10,294 to use the latest 1.x Dockerfile frontend from Docker Hub 514 , so newer syntax works even with an older Engine.