# Static Site Dockerfile Generator

URL: /dockerizer/static

Generate a Dockerfile that serves a folder of prebuilt HTML through unprivileged nginx or Caddy, with caching and security headers set.

## Default configuration

- `appName` (App name): static-site — Used for the image tag, the compose service and the OCI labels.

- `port` (Port): 8080 — 8080 rather than 80 so the server never needs root to bind it. Publish it as 80 with `-p 80:8080`.

- `outputDir` (Build output directory): dist — The folder holding your prebuilt HTML, relative to the Dockerfile.

- `webServer` (Web server): nginx

- `multiArch` (Multi-architecture build): false — Adds BUILDPLATFORM/TARGETARCH so `docker buildx build --platform linux/amd64,linux/arm64` cross-compiles natively.

- `healthcheck` (Healthcheck): true — Adds a HEALTHCHECK so orchestrators can restart an unresponsive container.

- `ociLabels` (OCI labels): false — Adds org.opencontainers.image.* metadata to the final image.

## Generated files

### Dockerfile

Multi-stage build: dependencies, compilation and the runtime image are separate, so only what the app needs at runtime ships.

```docker
# syntax=docker/dockerfile:1
# Generated by Easypanel Dockerizer — https://easypanel.io/dockerizer

# --- Runtime ------------------------------------------

# nginx-unprivileged runs as UID 101 and binds a high port, so no root is involved at any point
FROM nginxinc/nginx-unprivileged:stable-alpine AS runtime
COPY dist/ /usr/share/nginx/html/
COPY nginx.conf /etc/nginx/conf.d/default.conf
USER nginx
EXPOSE 8080
STOPSIGNAL SIGTERM

# Lets Docker, Compose and Easypanel see when the app is wedged
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
  CMD ["wget", "-q", "--spider", "http://127.0.0.1:8080/"]
CMD ["nginx", "-g", "daemon off;"]

```

### .dockerignore

Keeps the build context small and stops secrets and local dependencies from reaching an image layer.

```bash
# Version control
.git
.gitignore
.github

# Secrets — never bake these into an image layer
.env
.env.*
!.env.example
*.pem
*.key

# Editor and OS noise
.vscode
.idea
.DS_Store
Thumbs.db

# Docs and local tooling
README.md
LICENSE
docs
.editorconfig
docker-compose*.yml
Dockerfile*
.dockerignore

# Source and tooling — only the built output is copied in
node_modules
src
*.config.js
*.config.ts

```

### nginx.conf

Serves the built assets with a single-page-app fallback, long-lived asset caching and a never-cached index.html.

```nginx
server {
    listen 8080;
    listen [::]:8080;
    server_name _;

    root /usr/share/nginx/html;
    index index.html;

    # Single-page app fallback: unknown paths render index.html so client-side
    # routes survive a refresh or a direct link.
    location / {
        try_files $uri $uri/ /index.html;
    }

    # Fingerprinted build assets are safe to cache forever.
    location ~* \.(?:js|css|woff2?|ttf|otf|eot|svg|png|jpe?g|gif|webp|avif|ico)$ {
        expires 1y;
        add_header Cache-Control "public, immutable";
        access_log off;
        try_files $uri =404;
    }

    # index.html must never be cached or users get stuck on a stale bundle.
    location = /index.html {
        add_header Cache-Control "no-cache, no-store, must-revalidate";
    }

    gzip on;
    gzip_vary on;
    gzip_min_length 1024;
    gzip_types text/plain text/css text/javascript application/javascript application/json image/svg+xml;

    # Baseline hardening
    add_header X-Content-Type-Options "nosniff" always;
    add_header X-Frame-Options "SAMEORIGIN" always;
    add_header Referrer-Policy "strict-origin-when-cross-origin" always;
    server_tokens off;
}

```

### docker-compose.yml

Runs the image locally with its backing services, wired together and health-gated.

```yaml
services:
  app:
    build:
      context: .
      dockerfile: Dockerfile
    restart: unless-stopped
    ports:
      - "8080:8080"

```

## Frequently asked questions

### Should I build inside the image instead?

Usually yes — it makes the build reproducible and means CI does not have to produce the artefact first. Use the Vite, Astro or Angular generator if your site has a build step.

### nginx or Caddy?

nginx if you want the most widely understood config. Caddy if you want automatic Brotli and Gzip and a much shorter config file. Both are configured identically here.

## Related generators

- [Vite](/dockerizer/vite)

- [Astro](/dockerizer/astro)

- [React](/dockerizer/react)

- [Angular](/dockerizer/angular)