# syntax=docker/dockerfile:1.7 FROM python:3.12-slim ENV DEBIAN_FRONTEND=noninteractive WORKDIR /app # --- system deps with BuildKit caches to avoid space issues ------------------- RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \ --mount=type=cache,target=/var/lib/apt/lists,sharing=locked \ apt-get update \ && apt-get install -y --no-install-recommends curl git ca-certificates \ && update-ca-certificates # --- non-root runtime user ---------------------------------------------------- RUN useradd -m -s /bin/bash owi \ && mkdir -p /home/owi/.owi /data \ && chown -R owi:owi /home/owi /data # --- install uv --------------------------------------------------------------- ENV PATH="/root/.local/bin:${PATH}" RUN curl -fsSL https://astral.sh/uv/install.sh | sh \ && uv --version # --- copy metadata only (so deps layer is cacheable) -------------------------- COPY pyproject.toml uv.lock* Readme.md LICENSE* ./ # --- install dependencies only (skip local project) --------------------------- ARG OWILIX_EXTRAS=http RUN uv venv .venv \ && if [ -n "$OWILIX_EXTRAS" ]; then uv sync --frozen --extra "$OWILIX_EXTRAS" --no-install-project; else uv sync --frozen --no-install-project; fi \ && .venv/bin/python -c "import sys; print('VENV:', sys.executable)" # --- copy project sources ----------------------------------------------------- COPY owilix/ ./owilix/ # COPY any other src/package dirs if you have them # --- install the project itself ----------------------------------------------- RUN if [ -n "$OWILIX_EXTRAS" ]; then uv sync --frozen --extra "$OWILIX_EXTRAS"; else uv sync --frozen; fi \ && .venv/bin/owilix --help >/dev/null || true # --- runtime setup ------------------------------------------------------------ ENV PATH="/app/.venv/bin:${PATH}" ENV OWS_OWI_PATH=/home/owi/.owi ENV PYTHONPATH=/app VOLUME ["/home/owi/.owi", "/data"] EXPOSE 8080 USER owi ENTRYPOINT ["owilix"]