2023-12-01 09:56:26 -05:00
|
|
|
FROM python:3.11.4-alpine3.18 AS base
|
2024-03-05 14:31:58 +08:00
|
|
|
ARG TARGETPLATFORM
|
2023-06-08 13:12:00 +06:00
|
|
|
|
|
|
|
|
# Create a group and user to run an app
|
|
|
|
|
ENV APP_USER=appuser
|
2023-08-29 15:03:32 +08:00
|
|
|
RUN addgroup --system --gid 2000 ${APP_USER} && \
|
|
|
|
|
adduser --system --uid 1000 --ingroup ${APP_USER} ${APP_USER}
|
|
|
|
|
|
|
|
|
|
RUN apk add bash \
|
2024-03-05 14:31:58 +08:00
|
|
|
python3-dev \
|
|
|
|
|
build-base \
|
|
|
|
|
linux-headers \
|
|
|
|
|
pcre-dev \
|
|
|
|
|
mariadb-connector-c-dev \
|
|
|
|
|
libffi-dev \
|
|
|
|
|
git \
|
|
|
|
|
postgresql-dev
|
2022-06-03 08:09:47 -06:00
|
|
|
|
|
|
|
|
WORKDIR /etc/app
|
|
|
|
|
COPY ./requirements.txt ./
|
2024-03-05 14:31:58 +08:00
|
|
|
COPY ./grpcio-1.57.0-cp311-cp311-linux_aarch64.whl ./
|
|
|
|
|
|
|
|
|
|
# grpcio is not available for arm64 on pypi, so we need to install it from a local wheel
|
|
|
|
|
# this can be removed once https://github.com/grpc/grpc/issues/34998 is resolved
|
|
|
|
|
RUN if [ "$TARGETPLATFORM" = "linux/arm64" ]; then \
|
|
|
|
|
pip install grpcio-1.57.0-cp311-cp311-linux_aarch64.whl \
|
|
|
|
|
&& rm grpcio-1.57.0-cp311-cp311-linux_aarch64.whl; \
|
|
|
|
|
fi
|
2024-02-27 14:21:53 +00:00
|
|
|
|
|
|
|
|
# TODO: figure out how to get this to work.. see comment in .github/workflows/e2e-tests.yml
|
|
|
|
|
# https://stackoverflow.com/a/71846527
|
|
|
|
|
# RUN --mount=type=cache,target=/root/.cache/pip,from=pip_cache pip install -r requirements.txt
|
2022-06-03 08:09:47 -06:00
|
|
|
RUN pip install -r requirements.txt
|
|
|
|
|
|
2022-11-07 16:34:43 +01:00
|
|
|
# we intentionally have two COPY commands, this is to have the requirements.txt in a separate build step
|
|
|
|
|
# which only invalidates when the requirements.txt actually changes. This avoids having to unneccasrily reinstall deps (which is time-consuming)
|
|
|
|
|
# https://stackoverflow.com/questions/34398632/docker-how-to-run-pip-requirements-txt-only-if-there-was-a-change/34399661#34399661
|
2022-06-03 08:09:47 -06:00
|
|
|
COPY ./ ./
|
|
|
|
|
|
2023-05-22 20:16:31 +01:00
|
|
|
# Collect static files
|
2023-01-21 21:59:20 +08:00
|
|
|
RUN DJANGO_SETTINGS_MODULE=settings.prod_without_db DATABASE_TYPE=sqlite3 DATABASE_NAME=/var/lib/oncall/oncall.db SECRET_KEY="ThEmUsTSecretKEYforBUILDstage123" SILK_PROFILER_ENABLED="True" python manage.py collectstatic --no-input
|
2023-05-22 20:16:31 +01:00
|
|
|
|
2023-06-08 13:12:00 +06:00
|
|
|
# Change permissions for the app folder, as previous commands run as root
|
|
|
|
|
RUN chown -R ${APP_USER}:${APP_USER} /etc/app
|
|
|
|
|
|
2023-05-22 20:16:31 +01:00
|
|
|
# Create SQLite database and set permissions
|
|
|
|
|
RUN mkdir -p /var/lib/oncall
|
|
|
|
|
RUN DATABASE_TYPE=sqlite3 DATABASE_NAME=/var/lib/oncall/oncall.db python manage.py create_sqlite_db
|
2023-06-08 13:12:00 +06:00
|
|
|
RUN chown -R ${APP_USER}:${APP_USER} /var/lib/oncall
|
2022-10-04 09:25:53 +01:00
|
|
|
|
2023-01-26 20:33:04 +08:00
|
|
|
# This is required for silk profilers to sync between uwsgi workers
|
|
|
|
|
RUN mkdir -p /tmp/silk_profiles;
|
2023-06-08 13:12:00 +06:00
|
|
|
RUN chown -R ${APP_USER}:${APP_USER} /tmp/silk_profiles
|
|
|
|
|
|
|
|
|
|
# This is required for prometheus_client to sync between uwsgi workers
|
|
|
|
|
RUN mkdir -p /tmp/prometheus_django_metrics;
|
|
|
|
|
RUN chown -R ${APP_USER}:${APP_USER} /tmp/prometheus_django_metrics
|
|
|
|
|
ENV prometheus_multiproc_dir "/tmp/prometheus_django_metrics"
|
2023-01-26 20:33:04 +08:00
|
|
|
|
2023-09-07 05:38:19 -06:00
|
|
|
|
2022-11-07 16:34:43 +01:00
|
|
|
FROM base AS dev
|
2023-08-29 15:03:32 +08:00
|
|
|
RUN apk add sqlite mysql-client postgresql-client
|
2024-02-27 14:21:53 +00:00
|
|
|
# TODO: figure out how to get this to work.. see comment in .github/workflows/e2e-tests.yml
|
|
|
|
|
# https://stackoverflow.com/a/71846527
|
|
|
|
|
# RUN --mount=type=cache,target=/root/.cache/pip,from=pip_cache pip install -r requirements-dev.txt
|
2023-06-19 11:50:59 +02:00
|
|
|
RUN pip install -r requirements-dev.txt
|
2022-11-07 16:34:43 +01:00
|
|
|
|
2022-11-09 07:21:33 +01:00
|
|
|
FROM dev AS dev-enterprise
|
2024-02-27 14:21:53 +00:00
|
|
|
# TODO: figure out how to get this to work.. see comment in .github/workflows/e2e-tests.yml
|
|
|
|
|
# https://stackoverflow.com/a/71846527
|
|
|
|
|
# RUN --mount=type=cache,target=/root/.cache/pip,from=pip_cache pip install -r requirements-enterprise-docker.txt
|
2022-11-10 16:04:30 +01:00
|
|
|
RUN pip install -r requirements-enterprise-docker.txt
|
2022-11-09 07:21:33 +01:00
|
|
|
|
2022-11-07 16:34:43 +01:00
|
|
|
FROM base AS prod
|
2022-06-03 08:09:47 -06:00
|
|
|
|
2023-06-08 13:12:00 +06:00
|
|
|
# Change to a non-root user (number is required by Kubernetes runAsNonRoot check)
|
|
|
|
|
USER 1000
|
2022-06-03 08:09:47 -06:00
|
|
|
|
|
|
|
|
CMD [ "uwsgi", "--ini", "uwsgi.ini" ]
|