Dockerfile 2.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172
  1. # Build frontend
  2. FROM node:22-bookworm-slim AS frontend-builder
  3. WORKDIR /app/frontend
  4. # Copy package files first for better caching
  5. COPY frontend/package*.json ./
  6. # Use cache mount for npm
  7. RUN --mount=type=cache,target=/root/.npm \
  8. npm ci
  9. COPY frontend/ ./
  10. RUN npm run build
  11. # Production image
  12. FROM python:3.13-slim
  13. WORKDIR /app
  14. # Install system dependencies
  15. ENV DEBIAN_FRONTEND=noninteractive
  16. RUN apt-get update && apt-get install -y --no-install-recommends \
  17. curl \
  18. ffmpeg \
  19. iproute2 \
  20. libcap2-bin \
  21. && rm -rf /var/lib/apt/lists/* \
  22. && mkdir -p /etc/gnutls \
  23. && printf '[overrides]\ninsecure-hash = SHA1\n[priorities]\nSYSTEM = NORMAL:%%UNSAFE_RENEGOTIATION:%%COMPAT\n' > /etc/gnutls/config
  24. # Allow binding to privileged ports (e.g. 990/FTPS) as non-root user.
  25. # File capabilities are more reliable than Docker cap_add with user: directive,
  26. # which depends on ambient capability support in the container runtime.
  27. RUN setcap cap_net_bind_service=+ep "$(readlink -f /usr/local/bin/python3)"
  28. # Install Python dependencies with cache mount
  29. COPY requirements.txt ./
  30. RUN --mount=type=cache,target=/root/.cache/pip \
  31. pip install --root-user-action=ignore -r requirements.txt
  32. # Copy backend
  33. COPY backend/ ./backend/
  34. # Copy built frontend from builder stage
  35. COPY --from=frontend-builder /app/static ./static
  36. # Create data directory for persistent storage
  37. # chmod 777 allows running as non-root user (e.g., with docker compose user: directive)
  38. RUN mkdir -p /app/data /app/logs && chmod 777 /app/data /app/logs
  39. # Environment variables
  40. ENV PYTHONUNBUFFERED=1
  41. ENV DATA_DIR=/app/data
  42. ENV LOG_DIR=/app/logs
  43. ENV PORT=8000
  44. EXPOSE 3000
  45. EXPOSE 3002
  46. EXPOSE 8000
  47. EXPOSE 8883
  48. EXPOSE 9990
  49. EXPOSE 50000-50100
  50. # Health check (uses PORT env var via shell)
  51. HEALTHCHECK --interval=30s --timeout=10s --start-period=10s --retries=3 \
  52. CMD python -c "import urllib.request, os; urllib.request.urlopen(f'http://localhost:{os.environ.get(\"PORT\", \"8000\")}/health')" || exit 1
  53. # Run the application
  54. # Use standard asyncio loop (uvloop has permission issues in some Docker environments)
  55. # Port is configurable via PORT environment variable (default: 8000)
  56. CMD ["sh", "-c", "uvicorn backend.app.main:app --host 0.0.0.0 --port ${PORT:-8000} --loop asyncio"]