FROM python:3.11-slim ENV DEBIAN_FRONTEND=noninteractive # PostgreSQL + tools we need at runtime RUN apt-get update && apt-get install -y --no-install-recommends \ postgresql postgresql-contrib \ curl ca-certificates bash \ && rm -rf /var/lib/apt/lists/* # bore — open-source TCP tunnel, no signup (default). Arch-aware. RUN ARCH="$(dpkg --print-architecture)" \ && case "$ARCH" in \ amd64) BARCH=x86_64 ;; \ arm64) BARCH=aarch64 ;; \ *) BARCH=x86_64 ;; \ esac \ && curl -fsSL "https://github.com/ekzhang/bore/releases/download/v0.6.0/bore-v0.6.0-${BARCH}-unknown-linux-musl.tar.gz" \ -o /tmp/bore.tgz \ && tar -xzf /tmp/bore.tgz -C /usr/local/bin \ && rm /tmp/bore.tgz \ && chmod +x /usr/local/bin/bore # ngrok v3 — optional alternative tunnel (used only if NGROK_AUTHTOKEN is set) RUN ARCH="$(dpkg --print-architecture)" \ && curl -fsSL "https://bin.equinox.io/c/bNyj1mQVY4c/ngrok-v3-stable-linux-${ARCH}.tgz" \ -o /tmp/ngrok.tgz \ && tar -xzf /tmp/ngrok.tgz -C /usr/local/bin \ && rm /tmp/ngrok.tgz \ && chmod +x /usr/local/bin/ngrok # HF Spaces runs the container as uid 1000 — create a matching user RUN useradd -m -u 1000 appuser ENV HOME=/home/appuser WORKDIR /app COPY app/requirements.txt /app/requirements.txt RUN pip install --no-cache-dir -r /app/requirements.txt COPY app /app COPY start.sh /app/start.sh RUN chmod +x /app/start.sh \ && mkdir -p /home/appuser/data \ && chown -R appuser:appuser /home/appuser /app USER appuser ENV PGDATA=/home/appuser/data/pgdata \ POSTGRES_USER=demo \ POSTGRES_DB=demo \ PGPORT=5432 \ APP_PORT=7860 EXPOSE 7860 CMD ["/app/start.sh"]