Beiningw's picture
Session-mode live demo behind a pinned upstream clone
f8706b0 verified
Raw
History Blame Contribute Delete
1.9 kB
# Session-mode live demo for the self-reflective-apis prototype, shaped for a
# Hugging Face Docker Space (one container, app on port 7860).
#
# The Space repository carries OUR wrapper files only. The upstream repository
# is cloned at build time at a pinned commit, straight from its public GitHub
# home; it is never vendored into this repo, and the built image stays inside
# the platform that builds it -- it is not pushed to any registry.
#
# Layout inside the container (run_live.py):
# gate 0.0.0.0:7860 -> four pinned instances on 127.0.0.1:7861-7864,
# one per snapshot version; a visitor's drift position is a cookie-backed
# pointer at the gate, so every visitor drifts an isolated session.
#
# Required Space secret: LIVE_ADMIN_TOKEN (the gate fails closed without it).
FROM python:3.12-slim
RUN apt-get update \
&& apt-get install -y --no-install-recommends git \
&& rm -rf /var/lib/apt/lists/*
ENV PYTHONUNBUFFERED=1 \
PYTHONDONTWRITEBYTECODE=1 \
PIP_NO_CACHE_DIR=1
ARG UPSTREAM_REPO=https://github.com/arquicanedo/self-reflective-apis
ARG UPSTREAM_PIN=567b6a0e01b49de6b353eb32a3e2f6774052225e
WORKDIR /opt/live
RUN git clone --no-checkout "$UPSTREAM_REPO" _clone \
&& git -C _clone checkout --detach "$UPSTREAM_PIN"
COPY requirements-live.txt ./
RUN pip install --no-cache-dir -r requirements-live.txt
COPY live_app.py proxy_gate.py run_live.py live_page.html ./
RUN useradd --create-home --uid 10001 live \
&& mkdir -p runtime_data snapshots \
&& chown -R live:live /opt/live
USER live
# 7860 is the Space's app port; instances stay on loopback. Port 8000 is
# reserved by convention and never used here.
ENV LIVE_INSTANCE_PORTS=7861,7862,7863,7864 \
LIVE_PROXY_BIND=0.0.0.0 \
LIVE_PROXY_PORT=7860 \
LIVE_RATE_LIMIT_PER_MIN=600
EXPOSE 7860
CMD ["python", "run_live.py"]