File size: 1,455 Bytes
071ba6b
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# syntax=docker/dockerfile:1.7
FROM python:3.11-slim AS base

# System deps: gcc for any wheel builds, procps for ps (useful for REPL debug), tini for PID 1
RUN apt-get update && apt-get install -y --no-install-recommends \
    gcc \
    g++ \
    procps \
    tini \
    && rm -rf /var/lib/apt/lists/*

# Install uv (fast Python package installer)
RUN pip install --no-cache-dir uv==0.5.11

# Create non-root user (uid 1000) per STACK §7 — switched to AFTER the
# root-owned site-packages install completes.
RUN useradd --create-home --shell /bin/bash --uid 1000 fathom

WORKDIR /home/fathom/app

# Copy pyproject first for layer-cache efficiency
COPY --chown=fathom:fathom pyproject.toml ./
COPY --chown=fathom:fathom README.md ./

# Copy the package source before install so hatchling can build the wheel
COPY --chown=fathom:fathom env/ ./env/
COPY --chown=fathom:fathom openenv.yaml ./

# Install base deps as root into /usr/local (NO [train]/[viz] extras for
# env-server image — those are venue-side). Switching to non-root BEFORE
# this install would hit EACCES on /usr/local/lib/python3.11/site-packages.
RUN uv pip install --system --no-cache .

# Drop to non-root user (uid 1000) for runtime per STACK §7 threat model
USER fathom
ENV PATH="/home/fathom/.local/bin:${PATH}"

# HF Space default port
EXPOSE 7860

ENTRYPOINT ["/usr/bin/tini", "--"]
CMD ["python", "-m", "uvicorn", "env.server.app:app", "--host", "0.0.0.0", "--port", "7860"]