Repository navigation
Expand file tree
/
Copy pathDockerfile
More file actions
40 lines (29 loc) · 1.5 KB
/
Copy pathDockerfile
File metadata and controls
40 lines (29 loc) · 1.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
# Pinned to the multi-arch index digest of the tag, so a republished tag cannot
# change what the image is built from without a reviewed change here.
FROM python:3.11.17-slim-bookworm@sha256:2333bd330d12de02514770b3585cad313644316047cdee24a7acfdece6de6efb AS builder
WORKDIR /build
COPY pyproject.toml README.md LICENSE ./
COPY schemas/ schemas/
COPY src/ src/
# Build only this package's wheel. Its dependencies are installed in the
# runtime stage from the hash-pinned lock, so every package the image runs is
# pinned. Development extras and build tooling never cross into that stage.
RUN python -m pip wheel --disable-pip-version-check --no-deps --wheel-dir /wheels .
FROM python:3.11.17-slim-bookworm@sha256:2333bd330d12de02514770b3585cad313644316047cdee24a7acfdece6de6efb AS runtime
ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1
RUN groupadd --system --gid 10001 cmcp \
&& useradd --system --uid 10001 --gid cmcp --home-dir /var/lib/cmcp cmcp \
&& mkdir -p /etc/cmcp /var/lib/cmcp \
&& chown -R cmcp:cmcp /var/lib/cmcp
COPY --from=builder /wheels /wheels
COPY requirements/runtime.txt /tmp/runtime.txt
RUN python -m pip install --disable-pip-version-check --no-cache-dir \
--require-hashes -r /tmp/runtime.txt \
&& python -m pip install --disable-pip-version-check --no-cache-dir \
--no-index --no-deps /wheels/cmcp_runtime-*.whl \
&& rm -rf /wheels /tmp/runtime.txt
WORKDIR /var/lib/cmcp
USER 10001:10001
EXPOSE 8443
CMD ["cmcp", "start", "--config", "/etc/cmcp/config.yaml"]