# syntax=docker/dockerfile:1 # Pinned by digest so a rebuild of the same commit produces the same base. # Override with the PYTHON_BASE_IMAGE repository variable to move it forward # deliberately, and update this default in the same change. ARG PYTHON_BASE_IMAGE=python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9 FROM ${PYTHON_BASE_IMAGE} ARG VCS_REF=unknown LABEL org.opencontainers.image.title="DTF Portal/API" \ org.opencontainers.image.revision="$VCS_REF" \ org.opencontainers.image.source="DTF System repository" # The base is pinned, so its OS packages are frozen at the digest's build date. # Upgrade them here or the image ships known-fixed Debian vulnerabilities, which # is what the production image was doing while the local one already did this. RUN apt-get update \ && apt-get upgrade -y \ && rm -rf /var/lib/apt/lists/* WORKDIR /app COPY infra/requirements.txt infra/requirements.lock /app/infra/ RUN python -m pip install --no-cache-dir --require-hashes -r infra/requirements.lock COPY app /app/app COPY ops /app/ops RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin dtf USER 10001:10001 ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app EXPOSE 8000 CMD ["uvicorn", "app.app:app", "--host", "0.0.0.0", "--port", "8000", "--no-access-log"]