# Multi-stage build for ML Service FROM python:3.11-slim as builder # Install system dependencies RUN apt-get update && apt-get install -y \ tesseract-ocr \ tesseract-ocr-eng \ libgomp1 \ && rm -rf /var/lib/apt/lists/* # Create app directory WORKDIR /app # Copy requirements first for better caching COPY requirements.txt . # Install Python dependencies RUN pip install --no-cache-dir --upgrade pip && \ pip install --no-cache-dir -r requirements.txt # Production stage FROM python:3.11-slim # Install runtime dependencies RUN apt-get update && apt-get install -y \ tesseract-ocr \ tesseract-ocr-eng \ libgomp1 \ && rm -rf /var/lib/apt/lists/* # Create non-root user for security RUN useradd -m -u 1000 mluser && \ mkdir -p /app && \ chown -R mluser:mluser /app # Set working directory WORKDIR /app # Copy Python packages from builder COPY --from=builder /usr/local/lib/python3.11/site-packages /usr/local/lib/python3.11/site-packages COPY --from=builder /usr/local/bin /usr/local/bin # Copy application code COPY --chown=mluser:mluser . . # Switch to non-root user USER mluser # Expose port EXPOSE 8000 # Health check HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \ CMD python -c "import requests; requests.get('http://localhost:8000/health')" # Run the application CMD ["uvicorn", "app:app", "--host", "0.0.0.0", "--port", "7860"]