Files
dtf-system/deploy/Dockerfile.api
Cauê Faleiros 20403c5132
All checks were successful
Build and deploy / Validate source (push) Successful in 8s
Build and deploy / Integration suite on a real stack (push) Successful in 3m38s
Build and deploy / Secret scan and release gate (push) Successful in 7s
Build and deploy / Publish images (push) Successful in 1m2s
feat: daily encrypted database backup to a bucket of its own
A backup service runs pg_dump every day at 03:00 Brasília, checks the archive,
encrypts it with age to a public key and uploads it with a token for that
bucket only. The server cannot read or delete backups: the private key stays
with the owner, the bucket's lifecycle rule expires copies and its lock stops
early deletion. Each run is recorded and shown on the Kanban's Integrations
tab. tests/backup_test.py backs up, restores into a scratch database and
compares the rows in CI. Setup and restore: docs/BACKUP.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-29 18:49:21 -03:00

33 lines
1.5 KiB
Docker

# syntax=docker/dockerfile:1
# Pinned by digest so a rebuild of the same commit produces the same base.
# Override with the PYTHON_BASE_IMAGE repository variable to move it forward
# deliberately, and update this default in the same change.
ARG PYTHON_BASE_IMAGE=python:3.12-slim@sha256:2f17fc044b579bab302c2e8054d3a686e2cb9a83de48e70534b94cd8ebbe06a9
FROM ${PYTHON_BASE_IMAGE}
ARG VCS_REF=unknown
LABEL org.opencontainers.image.title="DTF Portal/API" \
org.opencontainers.image.revision="$VCS_REF" \
org.opencontainers.image.source="DTF System repository"
# The base is pinned, so its OS packages are frozen at the digest's build date.
# Upgrade them here or the image ships known-fixed Debian vulnerabilities, which
# is what the production image was doing while the local one already did this.
# pg_dump and age are for the database backup (ops/db_backup.py). Debian 13
# ships PostgreSQL 17, the server's major version, which pg_dump must match.
RUN apt-get update \
&& apt-get upgrade -y \
&& apt-get install -y --no-install-recommends postgresql-client-17 age \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /app
COPY infra/requirements.txt infra/requirements.lock /app/infra/
RUN python -m pip install --no-cache-dir --require-hashes -r infra/requirements.lock
COPY app /app/app
COPY ops /app/ops
RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin dtf
USER 10001:10001
ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app
EXPOSE 8000
CMD ["uvicorn", "app.app:app", "--host", "0.0.0.0", "--port", "8000", "--no-access-log"]