# HF Spaces runs the container as a non-root user; write only under paths we own. FROM python:3.11-slim RUN useradd -m -u 1000 user WORKDIR /app COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt COPY . . RUN mkdir -p /app/data && chown -R user:user /app USER user ENV ODC_LEDGER=/app/data/ledger.jsonl EXPOSE 7860 CMD ["uvicorn", "app:app", "--host", "0.0.0.0", "--port", "7860"]