mirror of
https://github.com/ChrisTitusTech/winutil.git
synced 2026-08-11 18:41:18 +10:00
Containerize docs site tooling for security and update documentation (#4942)
* Containerize the docs site's npm tooling Run Astro/Starlight dev, build, and preview commands through Docker (docs/Dockerfile, docker-compose.yml, service winutil-astro) instead of bare npm on the host, and document the required commands and rationale in docs/README.md. * Document Docker-only npm policy for agents Add a Dependency Installs, Builds, And Dev Servers section to AGENTS.md requiring docs/ tooling to run through Docker rather than directly on the host, point SPEC.md's Docs Site section at the new Dockerfile/docker-compose.yml, and renumber the remaining AGENTS.md sections to stay sequential. * Harden docs Docker dev environment Tightened docs-container safety and clarified contributor workflow. The docs Docker image now switches to the non-root `node` user after setting ownership, and compose now binds Astro to `127.0.0.1` instead of all interfaces. Updated AGENTS and docs README instructions to explain the security boundary of the bind mount and to require rebuilding plus `docker compose down -v` after dependency changes so `node_modules` is reseeded correctly. * Clarify docs secret handling in AGENTS Updates AGENTS.md to tighten docs security guidance: secrets must not be stored anywhere under `docs/`, because `docs/.dockerignore` only affects image build context and does not protect files from the Docker Compose bind mount used for docs dev/build commands. * Fix preview command to expose port in Docker The previous preview command didn't expose the port outside the container. Adding --service-ports and binding to 0.0.0.0 makes the preview server accessible from the host.
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
services:
|
||||
winutil-astro:
|
||||
build: .
|
||||
ports:
|
||||
- "127.0.0.1:4321:4321"
|
||||
volumes:
|
||||
- .:/app
|
||||
- astro_node_modules:/app/node_modules
|
||||
tmpfs:
|
||||
- /app/.astro
|
||||
environment:
|
||||
- CHOKIDAR_USEPOLLING=true
|
||||
- ASTRO_TELEMETRY_DISABLED=1
|
||||
|
||||
volumes:
|
||||
astro_node_modules:
|
||||
Reference in New Issue
Block a user