cacert 3.123 was installed first, but nodejs_22 pulls cacert 3.117 as a transitive dependency, causing a file conflict on ca-bundle.crt. Since all packages that need SSL certificates already pull cacert as a dependency, installing it explicitly is redundant and causes conflicts. Removing the explicit cacert install lets each package use its resolved transitive cacert version. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
42 lines
1.5 KiB
Docker
42 lines
1.5 KiB
Docker
FROM nixos/nix:latest
|
|
|
|
SHELL ["/bin/sh", "-c"]
|
|
|
|
ENV NIX_CONFIG="experimental-features = nix-command flakes"
|
|
|
|
# Install packages one at a time to avoid file conflicts in nix profile.
|
|
# When installing multiple packages simultaneously, nix may resolve
|
|
# different versions of shared dependencies (e.g., cacert 3.123 vs 3.117)
|
|
# which causes "An existing package already provides" errors.
|
|
# We install the big packages first (which pull their own cacert),
|
|
# then install standalone cacert last to upgrade, using --allow-import.
|
|
ARG NIXPKGS_COMMIT=64c08a7ca051951c8eae34e3e3cb1e202fe36786
|
|
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#nodejs_22"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#ffmpeg"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#python3"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#gnumake"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#gcc"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#pkg-config"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#vips"
|
|
RUN nix profile add "github:NixOS/nixpkgs/${NIXPKGS_COMMIT}#yt-dlp"
|
|
|
|
RUN corepack enable
|
|
|
|
WORKDIR /app
|
|
|
|
# Install deps from the app-local build context.
|
|
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml* ./
|
|
COPY vendor/discord-video-stream/package.json ./vendor/discord-video-stream/
|
|
COPY vendor/discord.js-selfbot-v13/package.json ./vendor/discord.js-selfbot-v13/
|
|
RUN pnpm install --no-frozen-lockfile
|
|
|
|
COPY . .
|
|
|
|
RUN pnpm run prepare:vendor
|
|
RUN pnpm run build
|
|
|
|
ENV NODE_ENV=production
|
|
|
|
CMD ["pnpm", "run", "start"]
|