30 lines
1.3 KiB
Docker
30 lines
1.3 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Pinned by digest so a rebuild of the same commit produces the same base.
|
|
# Override with the PYTHON_BASE_IMAGE repository variable to move it forward
|
|
# deliberately, and update this default in the same change.
|
|
ARG PYTHON_BASE_IMAGE=python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9
|
|
FROM ${PYTHON_BASE_IMAGE}
|
|
|
|
ARG VCS_REF=unknown
|
|
LABEL org.opencontainers.image.title="DTF Portal/API" \
|
|
org.opencontainers.image.revision="$VCS_REF" \
|
|
org.opencontainers.image.source="DTF System repository"
|
|
|
|
# The base is pinned, so its OS packages are frozen at the digest's build date.
|
|
# Upgrade them here or the image ships known-fixed Debian vulnerabilities, which
|
|
# is what the production image was doing while the local one already did this.
|
|
RUN apt-get update \
|
|
&& apt-get upgrade -y \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
COPY infra/requirements.txt infra/requirements.lock /app/infra/
|
|
RUN python -m pip install --no-cache-dir --require-hashes -r infra/requirements.lock
|
|
COPY app /app/app
|
|
COPY ops /app/ops
|
|
RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin dtf
|
|
USER 10001:10001
|
|
ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app
|
|
EXPOSE 8000
|
|
CMD ["uvicorn", "app.app:app", "--host", "0.0.0.0", "--port", "8000", "--no-access-log"]
|