Docker Builds and Private npm Packages

npm is an incredibly handy development tool. Allowing for breaking your projects up into separate modules keeps logic isolated, maintainable and composable – especially when working with a larger team. When working with proprietary software, we can supply specific URLs in the package to lock down permissions and keep the code out of the public npm registry. However, this can cause a problem when working with portable docker images as the git clone will fail due to a missing id_rsa.

The solution we’re using is quite simple. Provide an ssh id_rsa file to authorize the clone. Instead of using your personal id_rsa, it’s much more appropriate to create one specific for the application and then add the id_rsa.pub as an authorized deploy hook in your git provider. This way you don’t have someone’s actual id_rsa floating around in repositories. Here are the steps:

  1. In the project’s root directory create a .ssh folder.
  2. Run ssh-keygen -t rsa -C "some@nice.email"  and provide the absolute path to the new .ssh directory.
  3. Finally, add the public key as a deploy key for the module(s). This will authorize the read-only clone.

In the Dockerfile you’ll need to copy the .ssh directory in like so:

Note the  ssh-keyscan <your-git-provider> bit. It’s important to add this so SSH doesn’t try to, as it will want to prompt for your permission first which will cause the build to fail. Obviously, the git provider will be the domain for your repositories. If you’re using GitHub, it would be github.com.

If you notice an error that looks like this:

It’s probably because your syntax for the url in the package.json isn’t correct. Make sure the user is in the URL.

  • git://github.com/user/project.git#commit-ish
  • git+ssh://user@hostname:project.git#commit-ish
  • git+ssh://user@hostname/project.git#commit-ish
  • git+http://user@hostname/project/blah.git#commit-ish
  • git+https://user@hostname/project/blah.git#commit-ish

View the documentation here.

There you have it. Docker builds with private repositories.