# syntax=docker/dockerfile:1 ARG PYTHON_BASE_IMAGE=python:3.12-slim ARG NGINX_BASE_IMAGE=nginx:1.28-alpine FROM ${PYTHON_BASE_IMAGE} AS policy WORKDIR /build COPY dtf-site.html /build/dtf-site.html COPY local /build/local COPY deploy /build/deploy ENV NGINX_TEMPLATE=/build/deploy/nginx.conf.template RUN python local/compile_web.py FROM ${NGINX_BASE_IMAGE} ARG VCS_REF=unknown LABEL org.opencontainers.image.title="DTF Site and Kanban" \ org.opencontainers.image.revision="$VCS_REF" \ org.opencontainers.image.source="DTF System repository" ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https://invalid.example COPY --from=policy /build/default.conf.template /etc/nginx/templates/default.conf.template COPY dtf-site.html /usr/share/nginx/html/index.html COPY local/static/ /usr/share/nginx/html/ # The official entrypoint renders the server configuration at startup and Nginx # writes its PID/cache files. Keep the service non-root while granting it # ownership of only those runtime locations. This works in Docker Swarm, # where the previous read-only/tmpfs combination was not mounted as expected. RUN chown -R 101:101 /etc/nginx/conf.d /var/cache/nginx /run USER 101:101 EXPOSE 8080