# Use a slim Python base image FROM python:3.12-slim ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 # Create non-root user (optional but good practice) RUN useradd -m -u 1000 appuser WORKDIR /app # System deps (kept minimal since psycopg2-binary is used) RUN apt-get update && apt-get install -y --no-install-recommends \ curl ca-certificates && \ rm -rf /var/lib/apt/lists/* # Install Python deps first (better layer caching) COPY requirements.txt ./ RUN pip install --no-cache-dir -r requirements.txt # Copy application code COPY app ./app COPY README.md ./ # Ensure the non-root user can write to /app (for ./data sqlite, logs, etc.) RUN chown -R appuser:appuser /app # Hugging Face Spaces exposes $PORT; default to 7860 if not set ENV PORT=7860 EXPOSE 7860 # Ensure we run as non-root USER appuser SHELL ["/bin/bash", "-lc"] CMD uvicorn app.main:app --host 0.0.0.0 --port ${PORT:-7860}