Files
cleveragents-core/Dockerfile.server
T
HAL9000 927c5a4681
CI / lint (pull_request) Successful in 1m3s
CI / build (pull_request) Successful in 42s
CI / quality (pull_request) Successful in 1m13s
CI / typecheck (pull_request) Successful in 1m23s
CI / push-validation (pull_request) Successful in 24s
CI / helm (pull_request) Successful in 36s
CI / security (pull_request) Successful in 1m38s
CI / integration_tests (pull_request) Successful in 4m8s
CI / e2e_tests (pull_request) Successful in 5m11s
CI / unit_tests (pull_request) Successful in 7m27s
CI / docker (pull_request) Successful in 2m43s
CI / coverage (pull_request) Successful in 12m6s
CI / status-check (pull_request) Successful in 3s
CI / coverage (push) Blocked by required conditions
CI / docker (push) Blocked by required conditions
CI / status-check (push) Blocked by required conditions
CI / push-validation (push) Successful in 24s
CI / helm (push) Successful in 31s
CI / benchmark-publish (pull_request) Has been skipped
CI / build (push) Failing after 15m55s
CI / e2e_tests (push) Failing after 15m56s
CI / integration_tests (push) Failing after 15m58s
CI / unit_tests (push) Failing after 15m58s
CI / quality (push) Failing after 15m58s
CI / security (push) Failing after 15m58s
CI / typecheck (push) Failing after 16m0s
CI / lint (push) Failing after 16m2s
CI / benchmark-regression (push) Has been skipped
CI / benchmark-publish (push) Has started running
CI / benchmark-regression (pull_request) Successful in 1h3m8s
chore(ci): optimize Dockerfile layer order to cache Python dependency installation
Reorder COPY and RUN instructions in both Dockerfile and Dockerfile.server
to leverage Docker's layer caching for the dependency installation step.

Previously, pyproject.toml, README.md, and src/ were all copied together
before running uv pip install, meaning any source code change would
invalidate the dependency layer cache and force a full reinstall.

The new pattern copies only the dependency manifests (pyproject.toml and
uv.lock) first, installs the build tool in a cached layer, then copies
README.md and src/ for the actual wheel build. This ensures the
uv pip install step is only re-executed when pyproject.toml or uv.lock
change, not on every source code change.

ISSUES CLOSED: #1667
2026-04-26 10:02:20 +00:00

78 lines
2.8 KiB
Docker

# syntax=docker/dockerfile:1
# CleverAgents Server Dockerfile
# Multi-stage build for the ASGI server deployment.
# See k8s/README.md for Kubernetes deployment instructions.
# ---------------------------------------------------------------------------
# Stage 1: Build
# ---------------------------------------------------------------------------
# NOTE: Base images are pinned by tag (not by digest) for readability and
# ease of updates. Digest pinning provides stronger reproducibility but
# complicates routine version bumps. For production supply-chain security,
# consider switching to digest pinning or using a verified image registry.
FROM python:3.13-slim AS builder
# Install build dependencies
RUN apt-get update && apt-get install -y --no-install-recommends \
gcc \
&& rm -rf /var/lib/apt/lists/*
# Install uv for fast dependency resolution
COPY --from=ghcr.io/astral-sh/uv:0.8.0 /uv /usr/local/bin/uv
WORKDIR /app
# Copy dependency manifests first to leverage Docker layer caching.
# The expensive dependency installation step is only re-executed when
# pyproject.toml or uv.lock change, not on every source code change.
COPY pyproject.toml uv.lock ./
# Install build tool (separate layer for better caching) — this layer is
# cached as long as pyproject.toml and uv.lock remain unchanged.
RUN uv pip install --system build
# Copy remaining source files needed for the wheel build.
COPY README.md ./
COPY src/ ./src/
# Build wheel
RUN python -m build --wheel --outdir /dist
# ---------------------------------------------------------------------------
# Stage 2: Runtime
# ---------------------------------------------------------------------------
FROM python:3.13-slim
# Create non-root user (uid 1000 per spec)
RUN useradd -m -u 1000 appuser
# Install uv temporarily for fast package installation, then remove it
# to reduce attack surface in the runtime image.
COPY --from=ghcr.io/astral-sh/uv:0.8.0 /uv /usr/local/bin/uv
# Install the built wheel (includes uvicorn as a runtime dependency)
COPY --from=builder /dist/*.whl /tmp/
RUN uv pip install --system --no-cache /tmp/*.whl && \
rm -rf /tmp/* && \
rm /usr/local/bin/uv
# Create writable directories for runtime data
RUN mkdir -p /app/data && chown appuser:appuser /app/data
# Switch to non-root user
USER appuser
WORKDIR /app
# Expose the default server port
EXPOSE 8000
# Health check against the /health endpoint
# Note: Health checking in Kubernetes is handled by liveness/readiness
# probes configured in the Helm chart (k8s/values.yaml).
# Run the ASGI server through the project CLI entrypoint.
# This aligns with the specification's deployment contract:
# `python -m cleveragents`.
ENTRYPOINT ["python", "-m", "cleveragents"]
CMD ["server", "serve", "--app", "cleveragents.a2a.asgi:app", "--host", "0.0.0.0", "--port", "8000"]