The production image comes from the same Dockerfile, target runtime: dependencies without dev packages, the application files, UID 1000 and a health check (BookNest Dockerfile and Multi-Stage and BuildKit). Only the tag is new:
stage('Build image') {
steps {
sh 'docker build --target runtime -t "$IMAGE:$TAG" .'
}
}Output
+ docker build --target runtime -t localhost:32550/booknest-api:main-e2d7a8a-5 . ... #11 [runtime 4/6] COPY package.json app.js server.js ./ #11 CACHED ... #15 naming to localhost:32550/booknest-api:main-e2d7a8a-5 0.0s done
Every layer was CACHED, even the one holding the new app.js: the feature branch's last build (Reports and Notifications) had built the same files on the same daemon minutes earlier, so main got its image in five seconds. An agent with its own daemon (a pod, docker:dind) starts cold; --cache-from a registry tag restores the speed there. Building every branch also catches a broken Dockerfile before it is merged.