# Multi-stage Dockerfile for Red Head Python Backend # Build stage FROM python:3.9-slim as builder # Set working directory WORKDIR /app # Install system dependencies RUN apt-get update && apt-get install -y \ gcc \ && rm -rf /var/lib/apt/lists/* # Create a non-root user and group for building RUN groupadd --gid 1001 builder && \ useradd --uid 1001 --gid builder --shell /bin/bash --create-home builder # Switch to builder user for dependency installation USER builder WORKDIR /home/builder # Copy requirements and install Python dependencies in a virtual environment COPY src/server/requirements.txt . RUN python -m venv /home/builder/venv && \ /home/builder/venv/bin/pip install --no-cache-dir -r requirements.txt # Production stage FROM python:3.9-slim # Create a non-root user and group RUN groupadd --gid 1001 appuser && \ useradd --uid 1001 --gid appuser --shell /bin/bash --create-home appuser # Set working directory WORKDIR /app # Copy Python dependencies from builder stage (virtual environment) COPY --from=builder /home/builder/venv /app/venv # Copy application code COPY --chown=appuser:appuser src/server/ . # Copy website files COPY --chown=appuser:appuser src/website/ website/ # Create directory for cache if it doesn't exist RUN mkdir -p website/cache && \ chown -R appuser:appuser website/cache # Expose port EXPOSE 6006 # Set environment variables ENV FLASK_APP=app.py ENV FLASK_ENV=production ENV USER=appuser ENV PATH=/app/venv/bin:$PATH # Switch to non-root user USER appuser # Health check HEALTHCHECK --interval=30s --timeout=30s --start-period=5s --retries=3 \ CMD curl -f http://localhost:6006/api || exit 1 # Run the application CMD ["python", "app.py"]