FROM python:3.11-slim # Install system dependencies for zrok and Gradio RUN apt-get update && apt-get install -y curl wget jq && rm -rf /var/lib/apt/lists/* # Create a non‑root user (required by Hugging Face) RUN useradd -m -u 1000 user USER user ENV HOME=/home/user ENV PATH="/home/user/.local/bin:${PATH}" WORKDIR $HOME/app # Copy and install Python dependencies COPY --chown=user requirements.txt . RUN pip install --no-cache-dir --user -r requirements.txt # Download zrok binary from GitHub releases RUN curl -s https://api.github.com/repos/openziti/zrok/releases/latest \ | jq -r '.assets[] | select(.name | contains("linux_amd64.tar.gz")) | .browser_download_url' \ | wget -qi - && \ tar -xvf zrok*.tar.gz && \ mv zrok $HOME/.local/bin/ && \ rm zrok*.tar.gz # Copy your Gradio app COPY --chown=user app.py . # Expose the Gradio port (7860) EXPOSE 7860 # Start zrok (if token is provided) and then launch Gradio CMD ["sh", "-c", "\ if [ -n \"$ZROK_ENABLE_TOKEN\" ]; then \ echo 'Enabling zrok...'; \ zrok enable $ZROK_ENABLE_TOKEN; \ echo 'Starting zrok public share on port 7860...'; \ zrok share public http://localhost:7860 --backend-mode proxy & \ sleep 2; \ else \ echo 'Warning: ZROK_ENABLE_TOKEN is not set.'; \ fi; \ python app.py \ "]