Skip to content

Run on Bun: bun install, bun --bun next, standalone server under Bun - #8

Merged
ralyodio merged 1 commit into
mainfrom
chore/bun-runtime
Oct 1, 2026
Merged

ralyodio merged 1 commit into
mainfrom
chore/bun-runtime

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This moves recipepdfs.com off Node + pnpm onto Bun as the package manager, runtime and test runner. It follows the fleet recipe from the phonenumbers.bot pilot (profullstack/phonenumbers.bot#12).

Changes

  • Package manager: bun.lock replaces pnpm-lock.yaml, and packageManager is now bun@1.4.0.
  • Runtime: the scripts call bun --bun next .... next.config.ts sets output: "standalone" and pins outputFileTracingRoot.
  • Image: .nixpacks/Dockerfile is the path dev2's compose builds. It is now a hand-written oven/bun:1.4.0-slim multi-stage build that runs bun server.js as the non-root bun user. /app and /app/.data are owned by bun, so the JSON store (lib/store.ts) and public/uploads stay writable. Port 8080, env and the / health path are unchanged, and dev2's compose file needs no change. The nixpacks .nix and build.sh are removed.
  • Tests: vitest is replaced by bun test, which runs all 73 tests green. Imports now come from bun:test. The coinpay test drops vi.resetModules, which it never needed because the client reads env on each call. tsconfig lists types explicitly, because TypeScript 6 no longer picks up @types/* automatically.
  • CI: a new ci workflow runs a frozen install, typecheck, bun test and the build, then boots the standalone server under Bun.

Verified locally

I built the image from git archive HEAD through a compose file shaped like dev2's (same dockerfile path, env and 1g limit) and compared it with the live site:

  • All 13 pages and routes I checked return the same status codes. The api/v1/recipes and api/mcp bodies are byte-identical. The HTML differs only in chunk hashes.
  • Static CSS and /assets/* return 200, and Docker reports the container healthy.
  • docker top shows bun server.js, memory was about 128 MiB after 50 requests, the image is 348 MB (the Node image is 1.87 GB), and SIGTERM stops it in 0.3 s.

Pre-existing bug, unchanged here

robots.txt, llms.txt, /pricing and the POST /api/purchase redirect build absolute URLs from request.url. Next derives that URL from the server's bind hostname, not the request's Host. Live therefore already serves https://localhost:8080/..., and the standalone server will serve https://0.0.0.0:8080/... instead. Both are wrong. The fix is to use APP_URL, which is set to https://recipepdfs.com on dev2. That belongs in a follow-up PR, not this runtime swap.

🤖 Generated with Claude Code

Moves recipepdfs.com off Node + pnpm onto Bun, following the fleet recipe from
the phonenumbers.bot pilot.

- Package manager: bun.lock replaces pnpm-lock.yaml; packageManager bun@1.4.0.
- Runtime: scripts use `bun --bun next`, so Next builds and serves on Bun.
- Image: .nixpacks/Dockerfile (the path dev2's compose builds) is now a
  hand-written oven/bun:1.4.0-slim multi-stage build running the Next standalone
  server with `bun server.js` as the non-root bun user. /app and /app/.data are
  owned by bun so the JSON store and public/uploads stay writable. Port 8080,
  env and the / health path are unchanged. The nixpacks .nix and build.sh are gone.
- Tests: vitest becomes bun test. Imports move to bun:test; the coinpay test
  drops vi.resetModules (the client reads env per call) and uses spyOn.
  tsconfig lists types explicitly, since TypeScript 6 no longer picks up
  @types/* on its own.
- CI: new ci workflow (frozen install, typecheck, bun test, build, boot the
  standalone server under Bun).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

0 finding(s)

No findings.

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​types/​bun@​1.4.21001004892100
Updated@​types/​node@​25.9.2 ⏵ 25.9.810010081 +196100
Updatedtsx@​4.23.13 ⏵ 4.23.15100 +11008194100
Updatedposthog-js@​1.381.0 ⏵ 1.435.69810083 +1100 +1100
Updatedzod@​4.4.3 ⏵ 4.6.510010010095100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
License policy violation: npm bun-types under unrecognized license

License: unrecognized license - This license was not allowed or given any lesser classification by the applicable policy (package/docs/project/license.mdx)

From: package.json → npm/@types/bun@1.4.2 → npm/bun-types@1.4.2

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/bun-types@1.4.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@ralyodio
ralyodio merged commit b59f870 into main Oct 1, 2026
5 checks passed
@ralyodio
ralyodio deleted the chore/bun-runtime branch October 1, 2026 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant