Initial ThreatLens release
This commit is contained in:
Executable
+36
@@ -0,0 +1,36 @@
|
||||
# ──────────────────────────────────────────────────────────────
|
||||
# VulnForge — production Docker image
|
||||
# ──────────────────────────────────────────────────────────────
|
||||
FROM python:3.12-slim AS base
|
||||
|
||||
# Faster, cleaner Python in containers.
|
||||
ENV PYTHONUNBUFFERED=1 \
|
||||
PYTHONDONTWRITEBYTECODE=1 \
|
||||
PIP_NO_CACHE_DIR=1 \
|
||||
PIP_DISABLE_PIP_VERSION_CHECK=1 \
|
||||
TZ=UTC
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Install dependencies first to leverage Docker layer caching.
|
||||
COPY requirements.txt .
|
||||
RUN pip install --no-cache-dir -r requirements.txt
|
||||
|
||||
# Copy the rest of the application source.
|
||||
COPY . .
|
||||
|
||||
# Run as a non-root user for security; give it ownership of /app/data
|
||||
# so the SQLite DB + cache are writable (also mounted as a volume).
|
||||
RUN useradd --create-home --uid 10001 vulnforge \
|
||||
&& mkdir -p /app/data/cache \
|
||||
&& chown -R vulnforge:vulnforge /app
|
||||
USER vulnforge
|
||||
|
||||
# Persist SQLite DB + on-disk cache across restarts.
|
||||
VOLUME ["/app/data"]
|
||||
|
||||
# Lightweight liveness check: confirms the Python runtime + deps import OK.
|
||||
HEALTHCHECK --interval=5m --timeout=10s --start-period=30s --retries=3 \
|
||||
CMD python -c "import nextcord, aiohttp, aiosqlite" || exit 1
|
||||
|
||||
CMD ["python", "main.py"]
|
||||
Reference in New Issue
Block a user