|
|
|
|
|
|
|
|
FROM python:3.11-slim as builder |
|
|
|
|
|
|
|
|
RUN apt-get update && apt-get install -y \ |
|
|
gcc \ |
|
|
g++ \ |
|
|
git \ |
|
|
&& pip install --no-cache-dir uv \ |
|
|
&& rm -rf /var/lib/apt/lists/* \ |
|
|
&& apt-get clean |
|
|
|
|
|
|
|
|
WORKDIR /app |
|
|
|
|
|
|
|
|
COPY requirements.txt ./ |
|
|
|
|
|
|
|
|
RUN uv pip install --system -r requirements.txt \ |
|
|
&& pip cache purge \ |
|
|
&& find /usr/local/lib/python3.11/site-packages -name "*.pyc" -delete \ |
|
|
&& find /usr/local/lib/python3.11/site-packages -name "__pycache__" -type d -exec rm -rf {} + 2>/dev/null || true |
|
|
|
|
|
|
|
|
FROM python:3.11-slim |
|
|
|
|
|
|
|
|
RUN apt-get update && apt-get install -y \ |
|
|
curl \ |
|
|
&& rm -rf /var/lib/apt/lists/* |
|
|
|
|
|
|
|
|
RUN useradd -m -u 1000 appuser |
|
|
|
|
|
|
|
|
WORKDIR /app |
|
|
|
|
|
|
|
|
COPY --from=builder /usr/local/lib/python3.11/site-packages /usr/local/lib/python3.11/site-packages |
|
|
COPY --from=builder /usr/local/bin /usr/local/bin |
|
|
|
|
|
|
|
|
COPY --chown=appuser:appuser . . |
|
|
|
|
|
|
|
|
ARG ENVIRONMENT=production |
|
|
ENV ENVIRONMENT=${ENVIRONMENT} |
|
|
ENV PYTHONUNBUFFERED=1 |
|
|
ENV PYTHONDONTWRITEBYTECODE=1 |
|
|
|
|
|
|
|
|
RUN mkdir -p /app/logs /app/data && \ |
|
|
chown -R appuser:appuser /app |
|
|
|
|
|
|
|
|
USER appuser |
|
|
|
|
|
|
|
|
EXPOSE 8000 |
|
|
|
|
|
|
|
|
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \ |
|
|
CMD curl -f http://localhost:8000/health || exit 1 |
|
|
|
|
|
|
|
|
CMD ["uvicorn", "api.main:app", "--host", "0.0.0.0", "--port", "8000", "--workers", "4"] |