Files
2026-06-27 21:24:57 -04:00

37 lines
1.4 KiB
Docker
Executable File

# ──────────────────────────────────────────────────────────────
# VulnForge — production Docker image
# ──────────────────────────────────────────────────────────────
FROM python:3.12-slim AS base
# Faster, cleaner Python in containers.
ENV PYTHONUNBUFFERED=1 \
PYTHONDONTWRITEBYTECODE=1 \
PIP_NO_CACHE_DIR=1 \
PIP_DISABLE_PIP_VERSION_CHECK=1 \
TZ=UTC
WORKDIR /app
# Install dependencies first to leverage Docker layer caching.
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
# Copy the rest of the application source.
COPY . .
# Run as a non-root user for security; give it ownership of /app/data
# so the SQLite DB + cache are writable (also mounted as a volume).
RUN useradd --create-home --uid 10001 vulnforge \
&& mkdir -p /app/data/cache \
&& chown -R vulnforge:vulnforge /app
USER vulnforge
# Persist SQLite DB + on-disk cache across restarts.
VOLUME ["/app/data"]
# Lightweight liveness check: confirms the Python runtime + deps import OK.
HEALTHCHECK --interval=5m --timeout=10s --start-period=30s --retries=3 \
CMD python -c "import nextcord, aiohttp, aiosqlite" || exit 1
CMD ["python", "main.py"]