# syntax=docker/dockerfile:1 # CleverAgents Server Dockerfile # Multi-stage build for the ASGI server deployment. # See k8s/README.md for Kubernetes deployment instructions. # --------------------------------------------------------------------------- # Stage 1: Build # --------------------------------------------------------------------------- # NOTE: Base images are pinned by tag (not by digest) for readability and # ease of updates. Digest pinning provides stronger reproducibility but # complicates routine version bumps. For production supply-chain security, # consider switching to digest pinning or using a verified image registry. FROM python:3.13-slim AS builder # Install build dependencies RUN apt-get update && apt-get install -y --no-install-recommends \ gcc \ && rm -rf /var/lib/apt/lists/* # Install uv for fast dependency resolution COPY --from=ghcr.io/astral-sh/uv:0.8.0 /uv /usr/local/bin/uv WORKDIR /app # Copy project metadata and source code COPY pyproject.toml README.md ./ COPY src/ ./src/ # Install build tool (separate layer for better caching) RUN uv pip install --system build # Build wheel RUN python -m build --wheel --outdir /dist # --------------------------------------------------------------------------- # Stage 2: Runtime # --------------------------------------------------------------------------- FROM python:3.13-slim # Create non-root user (uid 1000 per spec) RUN useradd -m -u 1000 appuser # Install uv temporarily for fast package installation, then remove it # to reduce attack surface in the runtime image. COPY --from=ghcr.io/astral-sh/uv:0.8.0 /uv /usr/local/bin/uv # Install the built wheel (includes uvicorn as a runtime dependency) COPY --from=builder /dist/*.whl /tmp/ RUN uv pip install --system --no-cache /tmp/*.whl && \ rm -rf /tmp/* && \ rm /usr/local/bin/uv # Create writable directories for runtime data RUN mkdir -p /app/data && chown appuser:appuser /app/data # Switch to non-root user USER appuser WORKDIR /app # Expose the default server port EXPOSE 8000 # Health check against the /health endpoint # Note: Health checking in Kubernetes is handled by liveness/readiness # probes configured in the Helm chart (k8s/values.yaml). # Run the ASGI server through the project CLI entrypoint. # This aligns with the specification's deployment contract: # `python -m cleveragents`. ENTRYPOINT ["python", "-m", "cleveragents"] CMD ["server", "serve", "--app", "cleveragents.a2a.asgi:app", "--host", "0.0.0.0", "--port", "8000"]