Skip to content
UniKit

Dockerfile generator

Generate a multi-stage Dockerfile for Node, Python, Go, Java, Nginx or a static site, with an optional non-root user, EXPOSE port and version build args, plus a matching .dockerignore.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Base image and port

Three stages: install dependencies, build, then run — the artifact is copied from /app/dist.

Build options

Preview

Runtime
Node.js
Port
3000
Stages
3
Dockerfile
# syntax=docker/dockerfile:1

FROM node:22-alpine AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci

FROM node:22-alpine AS build
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
RUN npm run build

FROM node:22-alpine AS runtime
ENV NODE_ENV=production
WORKDIR /app
COPY package.json ./
RUN npm ci --omit=dev
COPY --from=build /app/dist ./dist
EXPOSE 3000
CMD ["node", "dist/index.js"]
.dockerignore
node_modules
dist
build
coverage
.git
.gitignore
.dockerignore
Dockerfile
docker-compose.yml
.env
.env.*
*.log

Multi-stage builds separate dependency installation from source copying: editing code no longer reinstalls dependencies, and the runtime stage ships only the artifact plus its runtime.

What this tool does

  • Containerise a new project with a working multi-stage Dockerfile instead of recalling npm ci and COPY --from from memory.
  • Turn a single-stage Dockerfile into a multi-stage one: the toolchain stays in the build stage and the runtime image ships only the artifact, often an order of magnitude smaller.
  • Add a security baseline by ticking the non-root option, which appends the USER instruction and the user-creation step, and switches nginx to the unprivileged image.
  • Export a matching .dockerignore so node_modules, .git and build output never enter the build context, keeping docker build fast.

Example

Input

Runtime: Node.js; port left empty; non-root and build args off; .dockerignore on

Output

# syntax=docker/dockerfile:1

FROM node:22-alpine AS deps
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci

FROM node:22-alpine AS build
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
RUN npm run build

FROM node:22-alpine AS runtime
ENV NODE_ENV=production
WORKDIR /app
COPY package.json ./
RUN npm ci --omit=dev
COPY --from=build /app/dist ./dist
EXPOSE 3000
CMD ["node", "dist/index.js"]

An empty port falls back to the runtime default (Node 3000, Python 8000, Go and Java 8080, nginx 80); enabling .dockerignore also renders a suggested ignore list.

Frequently asked questions

Why bother with multi-stage builds?

The toolchain — node_modules, Maven, the Go compiler — stays in the build stage while the runtime stage copies only the artifact and its runtime. The image typically shrinks by an order of magnitude, and dropping compilers and source code also shrinks the attack surface.

What do the non-root lines do?

The official node image ships a node user, so it only needs USER node; python and java images need a useradd step before switching to uid 10001; distroless images used for Go have a fixed nonroot uid 65532. nginx and static sites switch to the nginx-unprivileged image and port 8080, because a non-root process cannot bind port 80.

How do the build args work?

When enabled, the template declares ARG NODE_VERSION=22 and friends before the first FROM, so docker build --build-arg NODE_VERSION=20 . switches the base image version. An ARG declared before FROM is global and can be referenced by every stage.

Where does the .dockerignore file belong?

Next to the Dockerfile, in the root of the build context. It only decides which files are sent to docker build and never deletes anything inside the image; excluding node_modules, .git and build output speeds builds up noticeably.

Will the generated Dockerfile build as-is?

The templates follow the official images: npm ci expects package-lock.json, Go expects go.mod and go.sum, Java expects pom.xml plus a src directory. If your entry point differs — say src/server.js — adjust the COPY and CMD lines.

Keywords:dockerfiledockerfile generatorDockerfile 生成multi-stage builddockernode dockerfilepython dockerfilego dockerfiledockerignore容器镜像多阶段构建非 root 容器

Related tools