# Use the official Rejetto HFS image as the base FROM rejetto/hfs:v3.2.1 # Switch to root to configure permissions and users USER root # Create a non-root user 'user' with UID 1000 # We explicitly create the group first to ensure consistency RUN groupadd -g 1000 user && \ useradd -m -u 1000 -g user -d /home/user/app user # Set working directory WORKDIR /home/user/app # Create necessary directories for HFS and set permissions # /data for potential persistence, /home/user/app for the application RUN mkdir -p /data && \ chown -R user:user /home/user/app /data # Switch to the non-root user USER user # Expose the port used by Hugging Face Spaces EXPOSE 7860 # Copy the entrypoint script COPY entrypoint.sh /entrypoint.sh USER root RUN chmod +x /entrypoint.sh USER user # Set the custom entrypoint ENTRYPOINT ["/entrypoint.sh"] # Command to run HFS # We use the absolute path to the binary as found in the base image # default CMD passed to entrypoint CMD ["/opt/hfs/hfs", "--port", "7860", "--address", "0.0.0.0", "/data"] # version 3.2.1