1 ---
2 title: Docker and private modules
3 redirect_from:
4 - /private-modules/docker-and-private-modules
5 ---
6
7 To install private npm packages in a Docker container, you will need to use [Docker build secrets](https://docs.docker.com/develop/develop-images/build_enhancements/#new-docker-build-secret-information).
8
9 ## Background: runtime variables
10
11 You cannot install private npm packages in a Docker container using only runtime variables. Consider the following Dockerfile:
12
13 ```
14 FROM node
15
16 COPY package.json package.json
17 RUN npm install
18
19 # Add your source files
20 COPY . .
21 CMD npm start
22 ```
23
24 Which will use the official [Node.js](https://hub.docker.com/_/node) image, copy the `package.json` into our container, installs dependencies, copies the source files and runs the start command as specified in the `package.json`.
25
26 In order to install private packages, you may think that we could just add a line before we run `npm install`, using the [ENV parameter](https://docs.docker.com/engine/reference/builder/#env):
27
28 ```docker
29 ENV NPM_TOKEN=00000000-0000-0000-0000-000000000000
30 ```
31
32 However, this doesn't work as you would expect, because you want the npm install to occur when you run `docker build`, and in this instance, `ENV` variables aren't used, they are set for runtime only.
33
34 Instead of run-time variables, you must use Docker build secrets.
35
36 ## Update the Dockerfile
37
38 The Dockerfile that takes advantage of this has a few more lines in it than the earlier example that allows us to use your global `.npmrc` and the access token created when running `npm login` command (if you haven't run it already - do so before moving on).
39
40 ```dockerfile
41 # https://docs.npmjs.com/docker-and-private-modules
42 FROM node:18
43
44 ENV APP_HOME="/app"
45
46 WORKDIR ${APP_HOME}
47
48 COPY package*.json ${APP_HOME}/
49
50 RUN --mount=type=secret,id=npmrc,target=/root/.npmrc npm install
51
52 COPY . ${APP_HOME}/
53
54 CMD npm start
55
56 ```
57
58 This will configure your Dockerfile to receive `.npmrc` file via build secrets, that will leave no trace after npm dependency installation is done.
59
60 ## Build the Docker image
61
62 To build the image using the above Dockerfile and the npm authentication token, you can run the following command. Note the `.` at the end to give `docker build` the current directory as an argument.
63
64 ```shell
65 docker build . -t secure-app-secrets:1.0 --secret id=npmrc,src=$HOME/.npmrc
66 ```
67
68 This will build the Docker image with the access token coming from your global `.npmrc` file received via build secrets, so you can run `npm install` inside your container as the current logged-in user.
69
70 <Note>
71
72 **Note:** You may need to specify a working directory different from the default `/` otherwise some frameworks like Angular will fail.
73
74 </Note>