Upload Dockerfile with huggingface_hub
Browse files- Dockerfile +31 -0
Dockerfile
ADDED
|
@@ -0,0 +1,31 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
|
| 2 |
+
# Use a specific, slim Python version for a smaller and more secure image
|
| 3 |
+
FROM python:3.9-slim
|
| 4 |
+
|
| 5 |
+
# Create a non-root user for security best practices
|
| 6 |
+
# The -m flag creates the user's home directory
|
| 7 |
+
RUN useradd -m -u 1000 user
|
| 8 |
+
|
| 9 |
+
# Switch to the non-root user
|
| 10 |
+
USER user
|
| 11 |
+
|
| 12 |
+
# Set up the environment PATH for the non-root user to find installed packages
|
| 13 |
+
ENV PATH="/home/user/.local/bin:${PATH}"
|
| 14 |
+
|
| 15 |
+
# Set the working directory inside the container
|
| 16 |
+
WORKDIR /app
|
| 17 |
+
|
| 18 |
+
# Copy and install dependencies first to leverage Docker layer caching
|
| 19 |
+
# --chown ensures the 'user' owns the copied files, not 'root'
|
| 20 |
+
COPY --chown=user:user requirements.txt .
|
| 21 |
+
RUN pip install --no-cache-dir --upgrade -r requirements.txt
|
| 22 |
+
|
| 23 |
+
# Copy the rest of the application files, including app.py and the nutritional_db folder
|
| 24 |
+
COPY --chown=user:user . .
|
| 25 |
+
|
| 26 |
+
# Expose the port that Streamlit will run on (this is good practice for documentation)
|
| 27 |
+
EXPOSE 7860
|
| 28 |
+
|
| 29 |
+
# The command to run when the container starts.
|
| 30 |
+
# Runs the Streamlit app on the correct port and makes it available to the host.
|
| 31 |
+
CMD ["streamlit", "run", "app.py", "--server.port=7860", "--server.address=0.0.0.0"]
|