dec2d190ce
scripts/apply-db-init.sh implements the boot-time runner that walks db-init/*.sql in numeric-prefix order, applies each via psql, and records successful applications in a migrations_applied guard table so re-runs are no-ops. All 7 acceptance criteria pass live against the dev compose stack: empty dir, missing env var, apply, idempotent re-run, checksum mismatch, filename collision, broken SQL. Two retroactive Dockerfile corrections folded in (exposed by the first live-test attempt of 1.2's script): 1. apk add bash. The directus/directus:11.17.4 base is Alpine and ships ash via BusyBox, not bash. The script uses bash-specific features (associative arrays, [[ ]], mapfile, BASH_REMATCH) and fails at line 69 in sh. 2. .gitattributes added at repo root forcing LF on *.sh, *.sql, *.yaml, *.yml. Without it, Windows checkouts with core.autocrlf=true (the Git-for-Windows default) silently inject CRLF, causing "bad interpreter: /usr/bin/env bash^M" inside the Linux container. This failure mode only manifests in the container. Both corrections are documented in 01-project-scaffold.md's Done section; 02-db-init-runner.md's Done section captures the live-test results, the corrected docker compose run --entrypoint commands, and the gotcha about compose env defaults masking missing-env-var tests. ROADMAP marks 1.2 done; 1.3 next.
51 lines
2.2 KiB
Docker
51 lines
2.2 KiB
Docker
# syntax=docker/dockerfile:1.7
|
|
#
|
|
# TRM directus service image.
|
|
#
|
|
# Single-stage build for Phase 1. A multi-stage build (with a Node builder for
|
|
# extensions) lands in Phase 5 when TypeScript extensions are introduced.
|
|
#
|
|
# Artifacts baked into the image at build time:
|
|
# /directus/snapshots/ — schema.yaml (generated; empty placeholder in Phase 1)
|
|
# /directus/db-init/ — numbered SQL migration files (Phase 1 task 1.3 fills these)
|
|
# /directus/scripts/ — shell helpers (Phase 1 tasks 1.2, 1.6 fill these)
|
|
# /directus/extensions/ — TypeScript extensions (Phase 5)
|
|
# /directus/entrypoint.sh — boot wrapper (real flow lands in Phase 1 task 1.7)
|
|
#
|
|
# No bind mounts of these directories in compose.dev.yaml — the image is the
|
|
# source of truth. Reproducible across local, CI, and production environments.
|
|
|
|
FROM directus/directus:11.17.4
|
|
|
|
# Switch to root only for the setup steps; Directus's upstream image already
|
|
# drops to a non-root user — we preserve that for runtime.
|
|
USER root
|
|
|
|
# Install bash + postgresql-client.
|
|
# bash: scripts/apply-db-init.sh (task 1.2) uses bash-specific
|
|
# features (associative arrays, [[ ]], mapfile,
|
|
# BASH_REMATCH). Alpine ships ash via BusyBox, not bash —
|
|
# without this the script fails at line 1 (shebang) or
|
|
# line 69 (array declaration) depending on how it's run.
|
|
# postgresql16-client: provides psql + pg_isready, required by the db-init
|
|
# runner.
|
|
RUN apk add --no-cache bash postgresql16-client
|
|
|
|
# ---- Copy baked-in artifacts ----
|
|
# Each COPY is conditional on the directory existing at build time.
|
|
# .gitkeep files ensure the directories always exist so COPY never fails.
|
|
COPY snapshots/ /directus/snapshots/
|
|
COPY db-init/ /directus/db-init/
|
|
COPY scripts/ /directus/scripts/
|
|
COPY extensions/ /directus/extensions/
|
|
COPY entrypoint.sh /directus/entrypoint.sh
|
|
|
|
# Ensure the entrypoint is executable inside the image regardless of the host
|
|
# filesystem's permission bits.
|
|
RUN chmod +x /directus/entrypoint.sh
|
|
|
|
# Drop back to the non-root user the upstream image uses.
|
|
USER node
|
|
|
|
ENTRYPOINT ["/directus/entrypoint.sh"]
|