# Same pinned base as deploy/Dockerfile.api, so the integration suite exercises # the image that ships rather than a different one. FROM python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9 # pg_dump and age are for the database backup (ops/db_backup.py). Debian 13 # ships PostgreSQL 17, the server's major version, which pg_dump must match. RUN apt-get update \ && apt-get upgrade -y \ && apt-get install -y --no-install-recommends postgresql-client-17 age \ && rm -rf /var/lib/apt/lists/* WORKDIR /app COPY infra/requirements.txt infra/requirements.lock /app/infra/ RUN pip install --no-cache-dir --require-hashes -r infra/requirements.lock COPY app /app/app COPY ops /app/ops # The local image carries the suites so they can run inside the stack network. # deploy/Dockerfile.api deliberately does not: tests are not part of what ships. COPY tests /app/tests RUN useradd --uid 10001 --create-home dtf USER dtf ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1