This commit is contained in:
26
.gitea/workflows/docker.yaml
Normal file
26
.gitea/workflows/docker.yaml
Normal file
@@ -0,0 +1,26 @@
|
|||||||
|
name: Build and Push Docker Image
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [ "main" ]
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Login to Gitea Registry
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.REGISTRY_TOKEN }}" | docker login gitea.umbra.mom \
|
||||||
|
-u "${{ secrets.REGISTRY_USER }}" --password-stdin
|
||||||
|
|
||||||
|
- name: Build image
|
||||||
|
run: |
|
||||||
|
docker build -t gitea.umbra.mom/jay/pub-quiz:latest .
|
||||||
|
|
||||||
|
- name: Push image
|
||||||
|
run: |
|
||||||
|
docker push gitea.umbra.mom/jay/pub-quiz:latest
|
||||||
40
Dockerfile
40
Dockerfile
@@ -1,40 +1,22 @@
|
|||||||
# syntax=docker/dockerfile:1
|
FROM ghcr.io/astral-sh/uv:python3.13-bookworm-slim
|
||||||
FROM python:3.13-slim
|
|
||||||
|
|
||||||
# Pull uv binary from the official image (no pip overhead)
|
|
||||||
COPY --from=ghcr.io/astral-sh/uv:latest /uv /uvx /usr/local/bin/
|
|
||||||
|
|
||||||
# Non-root user for security
|
|
||||||
RUN adduser --disabled-password --no-create-home appuser
|
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
# Install dependencies first (layer is cached unless lock file changes)
|
# Copy dependency files first (better caching)
|
||||||
COPY pyproject.toml uv.lock ./
|
COPY pyproject.toml uv.lock ./
|
||||||
RUN uv sync --frozen --no-dev --no-install-project
|
|
||||||
|
|
||||||
# Copy application source
|
# Install dependencies into project environment
|
||||||
COPY src/ ./src/
|
RUN uv sync --frozen --no-dev
|
||||||
|
|
||||||
# data.csv is NOT baked into the image — it is mounted at runtime via docker-compose
|
# Copy app source
|
||||||
# so updates to the CSV don't require a rebuild.
|
COPY . .
|
||||||
|
|
||||||
RUN chown -R appuser:appuser /app
|
ENV PYTHONUNBUFFERED=1
|
||||||
USER appuser
|
|
||||||
|
|
||||||
# WORKDIR=/app → gunicorn CWD is /app → data.csv resolves to /app/data.csv (mounted volume)
|
|
||||||
# PYTHONPATH=/app/src → 'app' module resolves to src/app.py
|
|
||||||
ENV PYTHONPATH=/app/src
|
ENV PYTHONPATH=/app/src
|
||||||
|
ENV DATA_CSV_PATH=/app/data.csv
|
||||||
|
ENV UV_PROJECT_ENVIRONMENT=/app/.venv
|
||||||
|
ENV UV_LINK_MODE=copy
|
||||||
|
|
||||||
EXPOSE 8000
|
EXPOSE 8000
|
||||||
|
|
||||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
CMD ["uv", "run", "gunicorn", "--workers", "2", "--bind", "0.0.0.0:8000", "app:app"]
|
||||||
CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8000')"
|
|
||||||
|
|
||||||
CMD ["uv", "run", "--no-dev", "gunicorn", \
|
|
||||||
"--workers", "2", \
|
|
||||||
"--bind", "0.0.0.0:8000", \
|
|
||||||
"--access-logfile", "-", \
|
|
||||||
"--error-logfile", "-", \
|
|
||||||
"app:app"]
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user