47 lines
1.0 KiB
Docker
47 lines
1.0 KiB
Docker
# 多阶段构建 - SDLC Agent Demo
|
|
FROM python:3.11-slim as builder
|
|
|
|
# 设置工作目录
|
|
WORKDIR /app
|
|
|
|
# 设置环境变量
|
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
|
PYTHONUNBUFFERED=1 \
|
|
PIP_NO_CACHE_DIR=1 \
|
|
PIP_DISABLE_PIP_VERSION_CHECK=1
|
|
|
|
# 安装依赖
|
|
COPY requirements.txt .
|
|
RUN pip install --user --no-cache-dir -r requirements.txt
|
|
|
|
# 运行阶段
|
|
FROM python:3.11-slim
|
|
|
|
# 设置工作目录
|
|
WORKDIR /app
|
|
|
|
# 从 builder 阶段复制安装的包
|
|
COPY --from=builder /root/.local /root/.local
|
|
|
|
# 确保脚本路径在 PATH 中
|
|
ENV PATH=/root/.local/bin:$PATH \
|
|
PYTHONPATH=/app
|
|
|
|
# 复制应用代码
|
|
COPY . .
|
|
|
|
# 创建非 root 用户
|
|
RUN useradd -m -u 1000 appuser && \
|
|
chown -R appuser:appuser /app
|
|
USER appuser
|
|
|
|
# 暴露端口
|
|
EXPOSE 8000
|
|
|
|
# 健康检查
|
|
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
|
|
CMD python -c "import httpx; httpx.get('http://localhost:8000/health')" || exit 1
|
|
|
|
# 启动命令
|
|
CMD ["python", "-m", "uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]
|