Update Dockerfile
Browse files- Dockerfile +18 -13
Dockerfile
CHANGED
|
@@ -1,24 +1,29 @@
|
|
| 1 |
-
# Use
|
| 2 |
FROM python:3.9
|
| 3 |
|
| 4 |
-
|
| 5 |
-
|
| 6 |
-
|
| 7 |
-
# Copy all files from the current directory on the host to the container's /app directory
|
| 8 |
-
COPY . .
|
| 9 |
|
| 10 |
-
|
| 11 |
-
|
| 12 |
-
PATH=/home/user/.local/bin:$PATH
|
| 13 |
|
| 14 |
-
#
|
| 15 |
-
|
|
|
|
| 16 |
|
|
|
|
| 17 |
RUN useradd -m -u 1000 user
|
|
|
|
|
|
|
|
|
|
|
|
|
| 18 |
|
|
|
|
|
|
|
| 19 |
WORKDIR $HOME/app
|
| 20 |
|
| 21 |
-
|
|
|
|
| 22 |
|
| 23 |
-
#
|
| 24 |
CMD ["streamlit", "run", "app.py", "--server.port=8501", "--server.address=0.0.0.0", "--server.enableXsrfProtection=false"]
|
|
|
|
| 1 |
+
# Use Python 3.9 base
|
| 2 |
FROM python:3.9
|
| 3 |
|
| 4 |
+
ENV PYTHONDONTWRITEBYTECODE=1 \
|
| 5 |
+
PYTHONUNBUFFERED=1
|
|
|
|
|
|
|
|
|
|
| 6 |
|
| 7 |
+
# 1) Work as root (default)
|
| 8 |
+
WORKDIR /app
|
|
|
|
| 9 |
|
| 10 |
+
# 2) Copy only requirements first for better layer caching
|
| 11 |
+
COPY requirements.txt /app/requirements.txt
|
| 12 |
+
RUN pip3 install --no-cache-dir -r requirements.txt
|
| 13 |
|
| 14 |
+
# 3) Create the non-root user BEFORE switching to it
|
| 15 |
RUN useradd -m -u 1000 user
|
| 16 |
+
ENV HOME=/home/user
|
| 17 |
+
|
| 18 |
+
# 4) Prepare user home and app dir, set ownership
|
| 19 |
+
RUN mkdir -p $HOME/app && chown -R user:user $HOME
|
| 20 |
|
| 21 |
+
# 5) Now switch to the non-root user
|
| 22 |
+
USER user
|
| 23 |
WORKDIR $HOME/app
|
| 24 |
|
| 25 |
+
# 6) Copy the rest of the source as that user
|
| 26 |
+
COPY --chown=user:user . $HOME/app
|
| 27 |
|
| 28 |
+
# 7) Run your app
|
| 29 |
CMD ["streamlit", "run", "app.py", "--server.port=8501", "--server.address=0.0.0.0", "--server.enableXsrfProtection=false"]
|