v_2.3
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
# syntax=docker/dockerfile:1.7
|
||||
# ---- Build / runtime image -------------------------------------------------
|
||||
# python:3.13-slim-trixie is the current stable Debian-based slim variant.
|
||||
FROM python:3.13-slim-trixie
|
||||
|
||||
ENV PYTHONDONTWRITEBYTECODE=1 \
|
||||
PYTHONUNBUFFERED=1 \
|
||||
PIP_NO_CACHE_DIR=1 \
|
||||
PIP_DISABLE_PIP_VERSION_CHECK=1
|
||||
|
||||
# Install only what we strictly need (curl for healthchecks).
|
||||
# Use --no-install-recommends, then immediately purge apt lists to keep
|
||||
# the image small.
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends curl \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Create an unprivileged user
|
||||
RUN groupadd --system --gid 10001 alerthub \
|
||||
&& useradd --system --uid 10001 --gid alerthub --home-dir /app --shell /usr/sbin/nologin alerthub
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Install Python dependencies first (better layer cache)
|
||||
COPY --chown=alerthub:alerthub requirements.txt ./
|
||||
RUN pip install --upgrade pip \
|
||||
&& pip install --no-cache-dir -r requirements.txt
|
||||
|
||||
# Copy application sources
|
||||
COPY --chown=alerthub:alerthub app/ ./app/
|
||||
COPY --chown=alerthub:alerthub wsgi.py wsgi_frontoffice.py wsgi_backoffice.py entrypoint.sh ./
|
||||
|
||||
RUN chmod +x entrypoint.sh \
|
||||
&& mkdir -p /data \
|
||||
&& chown -R alerthub:alerthub /app /data
|
||||
|
||||
USER alerthub
|
||||
|
||||
EXPOSE 8080
|
||||
|
||||
# Start the unified app (frontoffice + /backoffice) on a single port.
|
||||
ENTRYPOINT ["./entrypoint.sh"]
|
||||
|
||||
HEALTHCHECK --interval=30s --timeout=4s --start-period=10s --retries=3 \
|
||||
CMD curl -fsS http://127.0.0.1:${FRONTOFFICE_PORT:-8080}/login >/dev/null || exit 1
|
||||
Reference in New Issue
Block a user