Refactor Dockerfile.n8n for improved npm package installation and env… - #100
Conversation
…ironment configuration - Updated the npm install command to install packages directly into n8n's app directory, enhancing organization and ownership management. - Replaced N8N_EXTERNAL_MODULES_ALLOWLIST with NODE_FUNCTION_ALLOW_EXTERNAL for better clarity in external module configuration. These changes streamline the Docker build process and improve the overall setup for the n8n service.
WalkthroughUpdates Dockerfile.n8n to install n8n system-wide under /usr/local/lib/node_modules/n8n, rename the external modules env var to NODE_FUNCTION_ALLOW_EXTERNAL, add a wget-based HEALTHCHECK probing /healthz, and run the container as the non-root Changes
Sequence Diagram(s)sequenceDiagram
autonumber
participant Docker as Docker Engine
participant Container as n8n Container
participant App as n8n App
participant Health as /healthz
Note over Container,App: Container start (USER=node)
Docker->>Container: start image
Container->>App: launch n8n (NODE_FUNCTION_ALLOW_EXTERNAL set, system-wide modules)
rect rgba(200,230,255,0.4)
Note over Docker,Container: periodic health check
Docker->>Container: exec wget -q --spider http://0.0.0.0:${N8N_PORT}/healthz
Container->>Health: GET /healthz
Health-->>Container: 200 OK / error
Container-->>Docker: exit 0 / non-zero
end
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested reviewers
Poem
📜 Recent review detailsConfiguration used: Path: .coderabbit.yml Review profile: CHILL Plan: Pro 💡 Knowledge Base configuration:
You can enable these sources in your CodeRabbit configuration. 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
✨ Finishing Touches🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR/Issue comments)Type Other keywords and placeholders
Status, Documentation and Community
|
There was a problem hiding this comment.
Actionable comments posted: 0
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
Dockerfile.n8n (1)
26-28: Healthcheck likely to fail: endpoint disabled by default, wget may be missing, and N8N_PORT isn’t exported at runtime.
- By default, /healthz is disabled unless you set QUEUE_HEALTH_CHECK_ACTIVE=true (and metrics often toggled with N8N_METRICS=true). (docs.n8n.io)
- Alpine images may not include wget; install it or use curl.
- N8N_PORT is only an ARG here, not an ENV, so ${N8N_PORT} will be empty at runtime inside /bin/sh -c.
Apply:
ARG N8N_PORT=5678 +ENV N8N_PORT=$N8N_PORT @@ -HEALTHCHECK --interval=30s --timeout=10s --retries=3 --start-period=30s \ - CMD ["/bin/sh", "-c", "wget -q --spider http://0.0.0.0:${N8N_PORT}/healthz || exit 1"] +# Enable health endpoints used by the healthcheck +ENV N8N_METRICS=true +ENV QUEUE_HEALTH_CHECK_ACTIVE=true +# Ensure wget is present for the healthcheck (or switch to curl) +USER root +RUN apk add --no-cache wget +USER node +HEALTHCHECK --interval=30s --timeout=10s --retries=3 --start-period=30s \ + CMD ["/bin/sh", "-c", "wget -q --spider http://127.0.0.1:${N8N_PORT}/healthz/readiness || exit 1"]Notes:
- readiness checks DB connectivity, which is usually a better container health signal. (docs.n8n.io)
🧹 Nitpick comments (1)
Dockerfile.n8n (1)
13-18: Install location is correct for Code node resolution; add minor hardening and clarity.
- Keep installing into n8n’s app folder so Code/Function nodes can require these modules.
- Optional tweaks:
- Add --omit=dev and --no-progress to reduce noise/size.
- Consider pinning exact versions (drop the carets) for reproducible builds.
- If future n8n upgrades replace /usr/local/lib/node_modules/n8n, document this coupling in the Dockerfile comments.
Apply if you agree:
-RUN npm install --no-audit --no-fund --ignore-scripts --prefix /usr/local/lib/node_modules/n8n \ +RUN npm install --no-audit --no-fund --ignore-scripts --omit=dev --no-progress \ + --prefix /usr/local/lib/node_modules/n8n \ showdown@${SHOWDOWN_VERSION} \ slackify-markdown@${SLACKIFY_MARKDOWN_VERSION} && \ npm cache clean --force && \ chown -R node:node /usr/local/lib/node_modules/n8n
📜 Review details
Configuration used: Path: .coderabbit.yml
Review profile: CHILL
Plan: Pro
💡 Knowledge Base configuration:
- MCP integration is disabled by default for public repositories
- Jira integration is disabled by default for public repositories
- Linear integration is disabled by default for public repositories
You can enable these sources in your CodeRabbit configuration.
📒 Files selected for processing (1)
Dockerfile.n8n(2 hunks)
🧰 Additional context used
📓 Path-based instructions (2)
Dockerfile.{n8n,temporal}
📄 CodeRabbit inference engine (.cursor/rules/docker-configuration.mdc)
Custom Docker images must be defined using Dockerfile.n8n and Dockerfile.temporal, each extending their respective official base images with custom configurations
Files:
Dockerfile.n8n
Dockerfile.n8n
📄 CodeRabbit inference engine (.cursor/rules/project-structure.mdc)
Use Dockerfile.n8n for custom n8n image configuration.
Files:
Dockerfile.n8n
🧠 Learnings (4)
📓 Common learnings
Learnt from: CR
PR: speedandfunction/automatization#0
File: .cursor/rules/project-structure.mdc:0-0
Timestamp: 2025-07-28T16:44:50.073Z
Learning: Applies to Dockerfile.n8n : Use Dockerfile.n8n for custom n8n image configuration.
📚 Learning: 2025-07-28T16:44:50.073Z
Learnt from: CR
PR: speedandfunction/automatization#0
File: .cursor/rules/project-structure.mdc:0-0
Timestamp: 2025-07-28T16:44:50.073Z
Learning: Applies to Dockerfile.n8n : Use Dockerfile.n8n for custom n8n image configuration.
Applied to files:
Dockerfile.n8n
📚 Learning: 2025-07-28T16:44:24.081Z
Learnt from: CR
PR: speedandfunction/automatization#0
File: .cursor/rules/docker-configuration.mdc:0-0
Timestamp: 2025-07-28T16:44:24.081Z
Learning: Applies to Dockerfile.{n8n,temporal} : Custom Docker images must be defined using Dockerfile.n8n and Dockerfile.temporal, each extending their respective official base images with custom configurations
Applied to files:
Dockerfile.n8n
📚 Learning: 2025-08-10T17:34:18.486Z
Learnt from: anatolyshipitz
PR: speedandfunction/automatization#93
File: Dockerfile.n8n:7-9
Timestamp: 2025-08-10T17:34:18.486Z
Learning: The n8nio/n8n Docker images (including version 1.89.2) are Alpine Linux-based, not Debian-based. Therefore, the correct package manager to use is `apk`, not `apt-get`. Commands like `apk add --no-cache git` are appropriate for installing packages in n8nio/n8n Docker images.
Applied to files:
Dockerfile.n8n
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (2)
- GitHub Check: Docker Security Scanning (n8n, Dockerfile.n8n, n8n-test:latest)
- GitHub Check: Service Availability Check
🔇 Additional comments (3)
Dockerfile.n8n (3)
31-31: Running as non-root looks good.Explicit USER node aligns with least-privilege best practices. No further action.
35-35: Comment-only change is fine.Leaving base image CMD intact is appropriate.
20-21: No legacy variable references found; approval granted.
🔍 Vulnerabilities of
|
| digest | sha256:babfe87d12278e28c261c012579068ab00fdb15d200ed3fe6a462106e5de80f2 |
| vulnerabilities | |
| platform | linux/amd64 |
| size | 404 MB |
| packages | 1734 |
📦 Base Image node:20-alpine
Description
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
| ||||||||||||||||
Description
|
|



…ironment configuration
These changes streamline the Docker build process and improve the overall setup for the n8n service.
Summary by CodeRabbit