-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile
More file actions
69 lines (52 loc) · 1.98 KB
/
Copy pathDockerfile
File metadata and controls
69 lines (52 loc) · 1.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
FROM python:3.12-slim AS builder
ENV PIP_INDEX_URL=https://mirrors.aliyun.com/pypi/simple/ \
PIP_TRUSTED_HOST=mirrors.aliyun.com
WORKDIR /app
# Install Poetry
RUN pip install --no-cache-dir poetry==1.8.4
# Copy dependency files and source (needed for poetry to install executor_core package)
COPY pyproject.toml poetry.lock ./
COPY src/ ./src/
# Install dependencies and the executor_core package itself
RUN poetry config virtualenvs.create false \
&& poetry install --no-dev --no-interaction --no-ansi
# Build stage
FROM python:3.12-slim AS runtime
WORKDIR /opt/taurus-executor
# Install runtime dependencies
RUN sed -i 's|http://deb.debian.org/debian|https://mirrors.aliyun.com/debian|g' /etc/apt/sources.list.d/debian.sources \
&& apt-get update && apt-get install -y --no-install-recommends \
curl make openssl \
&& rm -rf /var/lib/apt/lists/*
# Copy Python dependencies from builder
COPY --from=builder /usr/local/lib/python3.12/site-packages /usr/local/lib/python3.12/site-packages
COPY --from=builder /usr/local/bin /usr/local/bin
# Copy application code
COPY src/ ./src/
COPY proto/ ./proto/
COPY scripts/ ./scripts/
COPY manage/ ./manage/
COPY Makefile ./
COPY docker-entrypoint.sh ./docker-entrypoint.sh
RUN chmod +x ./docker-entrypoint.sh
# Generate gRPC code
RUN make build-all
# Create non-root user
RUN groupadd -r taurus && useradd -r -g taurus -d /opt/taurus-executor -s /sbin/nologin taurus
RUN chown -R taurus:taurus /opt/taurus-executor
# Entrypoint fixes volume permissions as root, then drops to taurus
ENTRYPOINT ["/opt/taurus-executor/docker-entrypoint.sh"]
# Environment variables
ENV PYTHONUNBUFFERED=1 \
PYTHONPATH=/opt/taurus-executor/src \
GRPC_HOST=0.0.0.0 \
GRPC_PORT=50051 \
LOG_LEVEL=INFO \
LOG_FORMAT=json
# Expose gRPC port
EXPOSE 50051
# Health check
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
CMD curl -f http://localhost:50051/ || exit 1
# Run the executor
CMD ["python", "-m", "executor_core.main"]