kartykp/gat-bypass-2fa-docs
@reggi/path-to-regexp
dependabot/npm_and_yarn/main/copy-to-clipboard-4.0.2
dependabot/npm_and_yarn/main/eslint-10.4.0
dependabot/npm_and_yarn/main/npmcli/eslint-config-7.0.0
dependabot/npm_and_yarn/main/proc-log-7.0.0
dependabot/npm_and_yarn/npm_and_yarn-826852524d
dependabot/npm_and_yarn/npm_and_yarn-ab9a7f4bc2
deprecate-totp-2fa
dhei/classic-tokens
gat-bypass-2fa-docs
jpg619/fix-accessibility-content-flow
jpg619/version-bump-tar-2
kartykp/gat-bypass-2fa-docs
kartykp/upgrade-path-to-regex
main
maitxn/version-bump-tar
patch-1
reggi/cache-based-on-version
reggi/dev-engines
reggi/fix-transform-prettier
reggi/overrides
update-search-sensitivity
| 1 | --- |
| 2 | title: Docker and private modules |
| 3 | redirect_from: |
| 4 | - /private-modules/docker-and-private-modules |
| 5 | --- |
| 6 | |
| 7 | To install private npm packages in a Docker container, you will need to use [Docker build secrets](https://docs.docker.com/build/building/secrets/#types-of-build-secrets). |
| 8 | |
| 9 | ## Background: runtime variables |
| 10 | |
| 11 | You cannot install private npm packages in a Docker container using only runtime variables. Consider the following Dockerfile: |
| 12 | |
| 13 | ``` |
| 14 | FROM node |
| 15 | |
| 16 | COPY package.json package.json |
| 17 | RUN npm install |
| 18 | |
| 19 | # Add your source files |
| 20 | COPY . . |
| 21 | CMD npm start |
| 22 | ``` |
| 23 | |
| 24 | Which will use the official [Node.js](https://hub.docker.com/_/node) image, copy the `package.json` into our container, installs dependencies, copies the source files and runs the start command as specified in the `package.json`. |
| 25 | |
| 26 | In order to install private packages, you may think that we could just add a line before we run `npm install`, using the [ENV parameter](https://docs.docker.com/engine/reference/builder/#env): |
| 27 | |
| 28 | ```docker |
| 29 | ENV NPM_TOKEN=00000000-0000-0000-0000-000000000000 |
| 30 | ``` |
| 31 | |
| 32 | However, this doesn't work as you would expect, because you want the npm install to occur when you run `docker build`, and in this instance, `ENV` variables aren't used, they are set for runtime only. |
| 33 | |
| 34 | Instead of run-time variables, you must use Docker build secrets. |
| 35 | |
| 36 | ## Update the Dockerfile |
| 37 | |
| 38 | The Dockerfile that takes advantage of this has a few more lines in it than the earlier example that allows us to use your global `.npmrc` and the access token created when running `npm login` command (if you haven't run it already - do so before moving on). |
| 39 | |
| 40 | ```dockerfile |
| 41 | # https://docs.npmjs.com/docker-and-private-modules |
| 42 | FROM node:18 |
| 43 | |
| 44 | ENV APP_HOME="/app" |
| 45 | |
| 46 | WORKDIR ${APP_HOME} |
| 47 | |
| 48 | COPY package*.json ${APP_HOME}/ |
| 49 | |
| 50 | RUN --mount=type=secret,id=npmrc,target=/root/.npmrc npm install |
| 51 | |
| 52 | COPY . ${APP_HOME}/ |
| 53 | |
| 54 | CMD npm start |
| 55 | |
| 56 | ``` |
| 57 | |
| 58 | This will configure your Dockerfile to receive `.npmrc` file via build secrets, that will leave no trace after npm dependency installation is done. |
| 59 | |
| 60 | ## Build the Docker image |
| 61 | |
| 62 | To build the image using the above Dockerfile and the npm authentication token, you can run the following command. Note the `.` at the end to give `docker build` the current directory as an argument. |
| 63 | |
| 64 | ```shell |
| 65 | docker build . -t secure-app-secrets:1.0 --secret id=npmrc,src=$HOME/.npmrc |
| 66 | ``` |
| 67 | |
| 68 | This will build the Docker image with the access token coming from your global `.npmrc` file received via build secrets, so you can run `npm install` inside your container as the current logged-in user. |
| 69 | |
| 70 | <Note> |
| 71 | |
| 72 | **Note:** You may need to specify a working directory different from the default `/` otherwise some frameworks like Angular will fail. |
| 73 | |
| 74 | </Note> |