FROM python:3.11-slim # Postgres client tools (pg_dump/psql) from PGDG — used by bootstrap_db.py to # clone the team schema into a fresh empty database on first boot. PGDG's # latest client can dump from any server version RDS is likely to run. RUN apt-get update \ && apt-get install -y --no-install-recommends curl ca-certificates gnupg \ && install -d /usr/share/postgresql-common/pgdg \ && curl -fsSL https://www.postgresql.org/media/keys/ACCC4CF8.asc \ -o /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc \ && . /etc/os-release \ && echo "deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.asc] http://apt.postgresql.org/pub/repos/apt ${VERSION_CODENAME}-pgdg main" \ > /etc/apt/sources.list.d/pgdg.list \ && apt-get update \ && apt-get install -y --no-install-recommends postgresql-client \ && rm -rf /var/lib/apt/lists/* WORKDIR /app COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt COPY . /app # The knowledge-graph files are rebuilt at runtime and served by Streamlit's # static file serving, which only reads ./static next to app.py. /app is # root-owned, so open this one directory to the non-root runtime user. RUN mkdir -p /app/static/kg && chmod -R a+rwx /app/static # HF Spaces run the container as a non-root user; keep all writes in /tmp. ENV HOME=/tmp \ AGENT_WORK_DIR=/tmp/agent_work \ PYTHONUNBUFFERED=1 \ STREAMLIT_BROWSER_GATHER_USAGE_STATS=false EXPOSE 7860 # bootstrap_db.py is a no-op unless BOOTSTRAP_CLONE_FROM is set, and is never # fatal — the app starts regardless (the agent fails safe on a bad schema). # run_space.py boots the agent (schema, scheduler, keep-alive) at process start # and then serves the Streamlit app in the same process, so cycles run from the # moment the container is up, with or without a visitor. CMD ["sh", "-c", "python bootstrap_db.py; exec python run_space.py"]