40 lines
1.2 KiB
Docker
40 lines
1.2 KiB
Docker
# ── builder ──────────────────────────────────────────────────────────────────
|
|
FROM python:3.12-slim AS builder
|
|
|
|
WORKDIR /build
|
|
|
|
COPY requirements.txt .
|
|
RUN pip install --upgrade pip && \
|
|
pip install --no-cache-dir --prefix=/install -r requirements.txt
|
|
|
|
# ── runtime ──────────────────────────────────────────────────────────────────
|
|
FROM python:3.12-slim AS runtime
|
|
|
|
# Non-root user
|
|
RUN addgroup --system appgroup && adduser --system --ingroup appgroup appuser
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy installed packages from builder
|
|
COPY --from=builder /install /usr/local
|
|
|
|
# Copy application source
|
|
COPY app/ app/
|
|
|
|
# Copy Alembic migration files
|
|
COPY alembic/ alembic/
|
|
COPY alembic.ini .
|
|
|
|
# Ensure appuser owns the working directory
|
|
RUN chown -R appuser:appgroup /app
|
|
|
|
USER appuser
|
|
|
|
EXPOSE 8000
|
|
|
|
CMD ["gunicorn", "app.main:app", \
|
|
"-k", "uvicorn.workers.UvicornWorker", \
|
|
"--bind", "0.0.0.0:8000", \
|
|
"--workers", "4", \
|
|
"--timeout", "120"]
|