# Production image for api/worker/beat - no bind mounts, no --reload, no # dev-only dependencies. See infrastructure/docker/api.Dockerfile for the # dev image (kept separate and untouched). FROM python:3.12-slim AS builder ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 \ PIP_NO_CACHE_DIR=1 WORKDIR /app RUN apt-get update && apt-get install -y --no-install-recommends \ build-essential \ && rm -rf /var/lib/apt/lists/* RUN python -m venv /venv ENV PATH="/venv/bin:$PATH" COPY apps/api /app RUN pip install --upgrade pip && pip install . FROM python:3.12-slim AS runtime ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 \ PATH="/venv/bin:$PATH" RUN useradd --create-home --uid 1000 appuser WORKDIR /app COPY --from=builder /venv /venv # --chown so appuser can actually write here - celery beat needs to write # its schedule state file (celerybeat-schedule) into the working directory, # and a plain COPY leaves everything root-owned even after USER switches # the running process to appuser. COPY --chown=appuser:appuser apps/api /app USER appuser EXPOSE 8000 CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]