Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions .github/workflows/gateway-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,9 +87,7 @@ jobs:
with:
node-version: 24
cache: npm
# package-lock.json is git-ignored for this SPA, so key the
# npm cache on package.json instead.
cache-dependency-path: gateway/internal/adminapi/ui/package.json
cache-dependency-path: gateway/internal/adminapi/ui/package-lock.json

- name: Install SPA dependencies
run: make ui-install
Expand Down
4 changes: 4 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -55,6 +55,10 @@ ecosystem.config.js

# Root level package-lock (empty, already ignored in mcp/)
package-lock.json
# The gateway admin SPA is npm-only and its image build runs `npm ci`
# from this lockfile so local, gateway-check CI and the release image
# all install the same tree (see gateway/Dockerfile plugin-ui-builder).
!gateway/internal/adminapi/ui/package-lock.json

.neo4j
.neo4j-*
Expand Down
8 changes: 5 additions & 3 deletions gateway/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -67,9 +67,11 @@ FROM node:${NODE_VERSION}-alpine3.23 AS plugin-ui-builder
WORKDIR /pui
COPY internal/adminapi/ui/package.json internal/adminapi/ui/package-lock.json* ./
# `--no-audit --no-fund` keeps the output quiet and a hair faster.
# Use `npm install` (not `ci`) until the lockfile exists; once the
# first build commits package-lock.json this switches to `npm ci`
# for reproducibility. The conditional below covers both.
# package-lock.json is committed (root .gitignore un-ignores it), so
# this takes the `npm ci` branch and installs exactly the tree that
# was type-checked locally and in gateway-check.yml. The `npm install`
# fallback only exists so a checkout with the lockfile stripped still
# builds — a fresh resolution is how the v0.4.262 build diverged.
RUN if [ -f package-lock.json ]; then npm ci --no-audit --no-fund; else npm install --no-audit --no-fund; fi
COPY internal/adminapi/ui/ ./
RUN npm run build
Expand Down
6 changes: 5 additions & 1 deletion gateway/Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -74,8 +74,12 @@ docker-logs:

UI_DIR = internal/adminapi/ui

# `npm ci`: install exactly what package-lock.json says (the lockfile is
# committed; the Dockerfile's plugin-ui-builder stage runs the same).
# Local dev that wants to bump a dependency runs `npm install` in
# $(UI_DIR) by hand and commits the lockfile change.
ui-install:
cd $(UI_DIR) && npm install --no-audit --no-fund
cd $(UI_DIR) && npm ci --no-audit --no-fund

ui-build:
cd $(UI_DIR) && npm run build
Expand Down
Loading
Loading