FROM python:3.12-slim as builder WORKDIR /build COPY requirements.txt . RUN pip install --no-cache-dir --user -r requirements.txt FROM python:3.12-slim WORKDIR /app RUN useradd -m -u 1000 appuser COPY --from=builder --chown=appuser:appuser /root/.local /home/appuser/.local COPY --chown=appuser:appuser app ./app COPY --chown=appuser:appuser main.py . # Download models during build instead of copying from local COPY scripts/model_download.bash /tmp/model_download.bash RUN pip install huggingface-hub && \ bash /tmp/model_download.bash && \ chown -R appuser:appuser models && \ rm /tmp/model_download.bash USER appuser ENV PATH=/home/appuser/.local/bin:$PATH \ PYTHONUNBUFFERED=1 EXPOSE 8000 CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]