Skip to content

Sync with docker-starter - #102

Merged
lyrixx merged 1 commit into
mainfrom
docker-starter-sync
Oct 5, 2026
Merged

lyrixx merged 1 commit into
mainfrom
docker-starter-sync

Conversation

@lyrixx

@lyrixx lyrixx commented Oct 5, 2026

Copy link
Copy Markdown
Member

Brings the infrastructure in line with the final version of docker-starter's production images (jolicode/docker-starter#442), which this project prototyped.

Changes

  • Local production stack (castor start -c prod) served on port 8000 instead of 8080, which collides with the Traefik admin port of the dev stack (README updated)
  • docker_exit_code() uses the context's run service (php in the prod context) instead of a hardcoded builder
  • Production build: the first composer install (dependencies layer) no longer dumps the autoloader, it is dumped once the sources are copied
  • php-fpm status page enabled (pm.status_path), denied by nginx by default, as in the starter
  • docker-compose.prod.yml: image and cache references use ${REGISTRY} like the starter (castor always sets it, image names are unchanged: ghcr.io/jolicode/monologue/{php,nginx})
  • build-push.yml: actions pinned by SHA, image tags computed in bash
  • CI: new prod-images job, which starts the production stack and checks the home page (behind HTTP Basic auth), a 404 on /index.php and that the php image runs as uid 1000
  • .home/.gitignore, .gitignore and .dockerignore aligned with the starter

Intentional differences with the starter

  • The app lives at the repository root (no application/), no Node/yarn, unconditional production build steps
  • Registry hardcoded in castor.php, overridable with REGISTRY in the prod context (same variable as the starter since Rename DS_REGISTRY to REGISTRY, and small fixes found while syncing projects docker-starter#445), as documented in the README
  • Newer versions than the starter are kept (debian, nginx, traefik, QA tools), as well as the project's QA config (PHP 8.4 migration rules, PHPStan baseline and Symfony extension) and Dependabot ecosystems

Validation

Locally: castor docker:build, castor --context=prod docker:build, castor app:install, qa:cs --dry-run, qa:twig-cs --dry-run, qa:phpstan, qa:security-audit and --context=test qa:phpunit all pass.

Not run locally: the production stack (castor start -c prod), so the new prod-images CI job has only been reviewed, not executed; the build-push.yml workflow only runs on main and tags.

* Serve the local production stack on port 8000 instead of 8080, which
  collides with the Traefik admin port of the dev stack
* Let docker_exit_code() use the context's run service (php in the prod
  context) instead of a hardcoded builder
* Do not dump the autoloader in the first composer install of the
  production build, it is dumped after the sources are copied
* Expose the php-fpm status page (denied by nginx by default)
* Pin the actions of the build-push workflow by SHA and compute the image
  tags in bash
* Test the production images in the CI
* Align .home/.gitignore, .gitignore and .dockerignore
@lyrixx
lyrixx merged commit 8c9f82c into main Oct 5, 2026
3 checks passed
@lyrixx
lyrixx deleted the docker-starter-sync branch October 5, 2026 09:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant