mirror of
https://github.com/suitenumerique/meet.git
synced 2026-09-29 21:15:07 +02:00
Builds through the Docker API of the Podman service receive none of the proxy variables in their RUN steps and fail systematically because of the proxy rejection. Plain HTTP connections are also rejected by the proxy with a HTTP 405 method error. - Passes http_proxy, https_proxy and no_proxy from the shell as build args - Make the Debian mirror of the agents image a build argument and override it for bureautix to force https usage
74 lines
1.7 KiB
Docker
74 lines
1.7 KiB
Docker
FROM python:3.14.6-slim AS base
|
|
|
|
# Install system dependencies required by LiveKit, fetching packages over HTTPS only for Bureautix proxy
|
|
RUN sed -i "s|^URIs: http://|URIs: https://|" /etc/apt/sources.list.d/debian.sources \
|
|
&& apt-get update && apt-get install -y --no-install-recommends \
|
|
libglib2.0-0 \
|
|
libgobject-2.0-0 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
|
|
# ---- Builder image ----
|
|
FROM base AS builder
|
|
|
|
ENV UV_COMPILE_BYTECODE=1 \
|
|
UV_LINK_MODE=copy \
|
|
UV_PYTHON_DOWNLOADS=0
|
|
|
|
# Install uv
|
|
COPY --from=ghcr.io/astral-sh/uv:0.10.9 /uv /uvx /bin/
|
|
|
|
WORKDIR /app
|
|
|
|
# Install production dependencies without the project itself (cacheable layer)
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
--mount=type=bind,source=uv.lock,target=uv.lock \
|
|
--mount=type=bind,source=pyproject.toml,target=pyproject.toml \
|
|
uv sync --locked --no-install-project --no-dev
|
|
|
|
# Install the project
|
|
COPY . /app
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --locked --no-dev
|
|
|
|
|
|
# ---- Development image ----
|
|
FROM base AS development
|
|
|
|
ENV UV_COMPILE_BYTECODE=1 \
|
|
UV_LINK_MODE=copy \
|
|
UV_PYTHON_DOWNLOADS=0
|
|
|
|
COPY --from=ghcr.io/astral-sh/uv:0.10.9 /uv /uvx /bin/
|
|
|
|
WORKDIR /app
|
|
|
|
COPY . /app
|
|
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --locked --all-extras
|
|
|
|
ENV PATH="/app/.venv/bin:$PATH"
|
|
|
|
CMD ["python", "multi_user_transcriber.py", "dev"]
|
|
|
|
|
|
# ---- Production image ----
|
|
FROM base AS production
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy the pre-built virtualenv and application source
|
|
COPY --from=builder /app /app
|
|
|
|
ENV PATH="/app/.venv/bin:$PATH"
|
|
|
|
# Remove pip to reduce attack surface in production
|
|
RUN pip uninstall -y pip
|
|
|
|
# Un-privileged user running the application
|
|
ARG DOCKER_USER
|
|
USER ${DOCKER_USER}
|
|
|
|
CMD ["python", "multi_user_transcriber.py", "start"]
|