# syntax=docker/dockerfile:1 # Multi-stage production build for the scopa app on the kaya framework. # Base: alpine:3.24 (python3 = 3.14). Deps come from the kaya Gitea registry # (primary) with PyPI as fallback. All binary deps (asyncpg, cryptography, # granian) ship musllinux wheels, so no compiler is strictly required; # build-base + python3-dev are kept in the builder only as a safety net and # are discarded in the runtime image. # # apk and pip both use BuildKit cache mounts (type=cache): the package # caches persist in the builder's cache across builds instead of being # re-downloaded, and never land in the image layers. Requires BuildKit # (default for `docker build` / `docker buildx` on modern daemons). # --- Builder --------------------------------------------------------------- FROM alpine:3.24 AS builder RUN --mount=type=cache,target=/var/cache/apk \ apk add python3 py3-pip build-base python3-dev WORKDIR /build COPY pyproject.toml README.md requirements.txt ./ COPY src/ ./src/ # aerich migration files are a release artifact: the db-migrate compose # service runs `aerich upgrade` from this image before the app starts. COPY migrations/ ./migrations/ RUN --mount=type=cache,target=/root/.cache/pip \ python3 -m venv /opt/venv \ && /opt/venv/bin/pip install --upgrade pip \ && /opt/venv/bin/pip install -r requirements.txt . # --- Runtime --------------------------------------------------------------- FROM alpine:3.24 RUN --mount=type=cache,target=/var/cache/apk \ apk add python3 ca-certificates tzdata \ && addgroup -S app && adduser -S -G app app COPY --from=builder /opt/venv /opt/venv COPY --from=builder /build/migrations /app/migrations # aerich reads [tool.aerich] from pyproject.toml (its default config file); # the db-migrate compose service runs `aerich upgrade` with working_dir=/app. COPY --from=builder /build/pyproject.toml /app/pyproject.toml ENV PATH="/opt/venv/bin:$PATH" \ PYTHONUNBUFFERED=1 \ PYTHONDONTWRITEBYTECODE=1 \ GRANIAN_HOST=0.0.0.0 \ GRANIAN_PORT=8080 \ GRANIAN_INTERFACE=rsgi USER app EXPOSE 8080 HEALTHCHECK --interval=30s --timeout=3s --start-period=10s \ CMD wget -q -O- http://127.0.0.1:8080/api/health || exit 1 CMD ["granian", "scopa.app:app"]