|
| 1 | +# Builder stage - has all build tools |
| 2 | +FROM condaforge/mambaforge AS builder |
| 3 | + |
| 4 | +WORKDIR /build |
| 5 | +COPY requirements.txt . |
| 6 | + |
| 7 | +# This is where pip will be after the conda environment is created |
| 8 | +ENV PIP=/opt/conda/envs/coordinator/bin/pip |
| 9 | + |
| 10 | +# Create conda environment and install dependencies |
| 11 | +RUN mamba create -n coordinator -y python=3.13.5 gcc \ |
| 12 | + && cd /tmp \ |
| 13 | + && git clone https://github.com/sunpy/sunpy.git \ |
| 14 | + && cd sunpy \ |
| 15 | + && git fetch origin pull/8500/head:pr-8500 \ |
| 16 | + && git checkout pr-8500 \ |
| 17 | + && mamba run -n coordinator pip install --no-cache-dir . \ |
| 18 | + && cd /build \ |
| 19 | + && mamba run -n coordinator pip install --no-cache-dir -r requirements.txt \ |
| 20 | + && rm -rf /tmp/sunpy |
| 21 | + |
| 22 | +# Final stage - minimal runtime image |
1 | 23 | FROM condaforge/mambaforge |
2 | 24 |
|
3 | 25 | RUN apt update && apt install -y curl |
4 | 26 |
|
5 | 27 | # Create and switch to non-root user |
6 | 28 | RUN useradd -m -s /bin/bash nonroot |
7 | 29 | WORKDIR /home/nonroot/app |
8 | | -USER nonroot |
| 30 | + |
| 31 | +# Copy conda environment from builder (keep same path) |
| 32 | +COPY --from=builder /opt/conda/envs/coordinator /opt/conda/envs/coordinator |
9 | 33 |
|
10 | 34 | # copy application files to the container |
11 | 35 | COPY --chown=nonroot:nonroot . . |
12 | 36 |
|
| 37 | +USER nonroot |
| 38 | + |
13 | 39 | # This is where pip will be after the conda environment is created |
14 | 40 | # can't conda activate in dockerfile |
15 | | -ENV PIP=/home/nonroot/.conda/envs/coordinator/bin/pip |
16 | | - |
17 | | -# Install dependencies in conda environment |
18 | | -RUN <<EOF |
19 | | -mamba create -n coordinator -y python=3.13.1 |
20 | | -$PIP install --no-cache-dir -r requirements.txt |
21 | | -EOF |
| 41 | +ENV PIP=/opt/conda/envs/coordinator/bin/pip |
22 | 42 |
|
23 | 43 | HEALTHCHECK --interval=2s --timeout=10s \ |
24 | 44 | CMD curl --silent --fail "http://127.0.0.1/health-check" |
25 | 45 |
|
26 | | -ENTRYPOINT ["/home/nonroot/.conda/envs/coordinator/bin/python"] |
| 46 | +ENTRYPOINT ["/opt/conda/envs/coordinator/bin/python"] |
27 | 47 |
|
28 | 48 | CMD ["-m", "fastapi", "run", "--workers", "4", "--port", "80", "main.py"] |
0 commit comments