927c5a4681
CI / lint (pull_request) Successful in 1m3s
CI / build (pull_request) Successful in 42s
CI / quality (pull_request) Successful in 1m13s
CI / typecheck (pull_request) Successful in 1m23s
CI / push-validation (pull_request) Successful in 24s
CI / helm (pull_request) Successful in 36s
CI / security (pull_request) Successful in 1m38s
CI / integration_tests (pull_request) Successful in 4m8s
CI / e2e_tests (pull_request) Successful in 5m11s
CI / unit_tests (pull_request) Successful in 7m27s
CI / docker (pull_request) Successful in 2m43s
CI / coverage (pull_request) Successful in 12m6s
CI / status-check (pull_request) Successful in 3s
CI / coverage (push) Blocked by required conditions
CI / docker (push) Blocked by required conditions
CI / status-check (push) Blocked by required conditions
CI / push-validation (push) Successful in 24s
CI / helm (push) Successful in 31s
CI / benchmark-publish (pull_request) Has been skipped
CI / build (push) Failing after 15m55s
CI / e2e_tests (push) Failing after 15m56s
CI / integration_tests (push) Failing after 15m58s
CI / unit_tests (push) Failing after 15m58s
CI / quality (push) Failing after 15m58s
CI / security (push) Failing after 15m58s
CI / typecheck (push) Failing after 16m0s
CI / lint (push) Failing after 16m2s
CI / benchmark-regression (push) Has been skipped
CI / benchmark-publish (push) Has started running
CI / benchmark-regression (pull_request) Successful in 1h3m8s
Reorder COPY and RUN instructions in both Dockerfile and Dockerfile.server to leverage Docker's layer caching for the dependency installation step. Previously, pyproject.toml, README.md, and src/ were all copied together before running uv pip install, meaning any source code change would invalidate the dependency layer cache and force a full reinstall. The new pattern copies only the dependency manifests (pyproject.toml and uv.lock) first, installs the build tool in a cached layer, then copies README.md and src/ for the actual wheel build. This ensures the uv pip install step is only re-executed when pyproject.toml or uv.lock change, not on every source code change. ISSUES CLOSED: #1667
78 lines
2.8 KiB
Docker
78 lines
2.8 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# CleverAgents Server Dockerfile
|
|
# Multi-stage build for the ASGI server deployment.
|
|
# See k8s/README.md for Kubernetes deployment instructions.
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Stage 1: Build
|
|
# ---------------------------------------------------------------------------
|
|
# NOTE: Base images are pinned by tag (not by digest) for readability and
|
|
# ease of updates. Digest pinning provides stronger reproducibility but
|
|
# complicates routine version bumps. For production supply-chain security,
|
|
# consider switching to digest pinning or using a verified image registry.
|
|
FROM python:3.13-slim AS builder
|
|
|
|
# Install build dependencies
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
gcc \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Install uv for fast dependency resolution
|
|
COPY --from=ghcr.io/astral-sh/uv:0.8.0 /uv /usr/local/bin/uv
|
|
|
|
WORKDIR /app
|
|
|
|
# Copy dependency manifests first to leverage Docker layer caching.
|
|
# The expensive dependency installation step is only re-executed when
|
|
# pyproject.toml or uv.lock change, not on every source code change.
|
|
COPY pyproject.toml uv.lock ./
|
|
|
|
# Install build tool (separate layer for better caching) — this layer is
|
|
# cached as long as pyproject.toml and uv.lock remain unchanged.
|
|
RUN uv pip install --system build
|
|
|
|
# Copy remaining source files needed for the wheel build.
|
|
COPY README.md ./
|
|
COPY src/ ./src/
|
|
|
|
# Build wheel
|
|
RUN python -m build --wheel --outdir /dist
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Stage 2: Runtime
|
|
# ---------------------------------------------------------------------------
|
|
FROM python:3.13-slim
|
|
|
|
# Create non-root user (uid 1000 per spec)
|
|
RUN useradd -m -u 1000 appuser
|
|
|
|
# Install uv temporarily for fast package installation, then remove it
|
|
# to reduce attack surface in the runtime image.
|
|
COPY --from=ghcr.io/astral-sh/uv:0.8.0 /uv /usr/local/bin/uv
|
|
|
|
# Install the built wheel (includes uvicorn as a runtime dependency)
|
|
COPY --from=builder /dist/*.whl /tmp/
|
|
RUN uv pip install --system --no-cache /tmp/*.whl && \
|
|
rm -rf /tmp/* && \
|
|
rm /usr/local/bin/uv
|
|
|
|
# Create writable directories for runtime data
|
|
RUN mkdir -p /app/data && chown appuser:appuser /app/data
|
|
|
|
# Switch to non-root user
|
|
USER appuser
|
|
WORKDIR /app
|
|
|
|
# Expose the default server port
|
|
EXPOSE 8000
|
|
|
|
# Health check against the /health endpoint
|
|
# Note: Health checking in Kubernetes is handled by liveness/readiness
|
|
# probes configured in the Helm chart (k8s/values.yaml).
|
|
|
|
# Run the ASGI server through the project CLI entrypoint.
|
|
# This aligns with the specification's deployment contract:
|
|
# `python -m cleveragents`.
|
|
ENTRYPOINT ["python", "-m", "cleveragents"]
|
|
CMD ["server", "serve", "--app", "cleveragents.a2a.asgi:app", "--host", "0.0.0.0", "--port", "8000"]
|