Sets up everything needed to deploy behind Cloudflare with a self-hosted git server: multi-stage prod Dockerfiles (non-root), docker-compose.prod.yml (Postgres/Redis with no host ports, Nginx reverse proxy, Gitea with public-read/admin-write access control), scripts/bootstrap-env.sh to auto-generate required secrets on first clone, and DEPLOYMENT.md covering the full runbook. Provider API keys (Anthropic/Brave/NinjaPear/USPTO/ Turnstile) are deliberately kept out of .env in favor of the existing DB-backed Settings UI, so the public repo stays safe to expose. Also fixes two bugs only surfaced by live-testing the prod stack: Celery beat couldn't write its schedule file as a non-root user, and Gitea's embedded SSH server conflicted with the base image's own sshd on port 22. Co-Authored-By: Claude Sonnet 5 <[email protected]>
45 lines
1.1 KiB
Docker
45 lines
1.1 KiB
Docker
# Production image for api/worker/beat - no bind mounts, no --reload, no
|
|
# dev-only dependencies. See infrastructure/docker/api.Dockerfile for the
|
|
# dev image (kept separate and untouched).
|
|
|
|
FROM python:3.12-slim AS builder
|
|
|
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
|
PYTHONUNBUFFERED=1 \
|
|
PIP_NO_CACHE_DIR=1
|
|
|
|
WORKDIR /app
|
|
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
build-essential \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
RUN python -m venv /venv
|
|
ENV PATH="/venv/bin:$PATH"
|
|
|
|
COPY apps/api /app
|
|
RUN pip install --upgrade pip && pip install .
|
|
|
|
|
|
FROM python:3.12-slim AS runtime
|
|
|
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
|
PYTHONUNBUFFERED=1 \
|
|
PATH="/venv/bin:$PATH"
|
|
|
|
RUN useradd --create-home --uid 1000 appuser
|
|
|
|
WORKDIR /app
|
|
COPY --from=builder /venv /venv
|
|
# --chown so appuser can actually write here - celery beat needs to write
|
|
# its schedule state file (celerybeat-schedule) into the working directory,
|
|
# and a plain COPY leaves everything root-owned even after USER switches
|
|
# the running process to appuser.
|
|
COPY --chown=appuser:appuser apps/api /app
|
|
|
|
USER appuser
|
|
|
|
EXPOSE 8000
|
|
|
|
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
|