Docker hardening (non-root, healthcheck, .dockerignore, log caps) + UI table/typography polish
This commit is contained in:
parent
e586bc92e7
commit
bb5d50502c
6 changed files with 84 additions and 8 deletions
15
Dockerfile
15
Dockerfile
|
|
@ -1,5 +1,10 @@
|
|||
FROM python:3.12-slim
|
||||
|
||||
# Logs reach `docker logs` the moment they're printed rather than whenever a
|
||||
# buffer happens to flush — without this, a crash can eat the lines that
|
||||
# explain it.
|
||||
ENV PYTHONUNBUFFERED=1
|
||||
|
||||
# Only optional deps (see README) — the app itself is stdlib only.
|
||||
RUN pip install --no-cache-dir anthropic pillow
|
||||
|
||||
|
|
@ -13,4 +18,14 @@ ENV CARD_GRADER_DB_PATH=/data/grades.db
|
|||
ENV PORT=8778
|
||||
EXPOSE 8778
|
||||
|
||||
# nobody:users — Unraid's appdata convention. Running as root inside the
|
||||
# container was needless: the app needs exactly one writable path (/data),
|
||||
# so give it only that. The host ./data dir must be owned 99:100 to match.
|
||||
USER 99:100
|
||||
|
||||
# python (not curl — slim image doesn't ship it) probing the app's own root.
|
||||
# BASE_PATH doesn't affect this: un-prefixed paths still route normally.
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
CMD ["python3", "-c", "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:8778/', timeout=4).status == 200 else 1)"]
|
||||
|
||||
CMD ["python3", "app.py"]
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue