Optimize runner Docker image building
All checks were successful
Docker Build and Push (Multi-architecture) / build-and-push (push) Successful in 19m17s
All checks were successful
Docker Build and Push (Multi-architecture) / build-and-push (push) Successful in 19m17s
This commit is contained in:
14
.dockerignore
Normal file
14
.dockerignore
Normal file
@@ -0,0 +1,14 @@
|
|||||||
|
.gitea
|
||||||
|
.gitignore
|
||||||
|
.env
|
||||||
|
__pycache__
|
||||||
|
md_images
|
||||||
|
*.pyc
|
||||||
|
*.pyo
|
||||||
|
*.pyd
|
||||||
|
*.ini
|
||||||
|
*.sample
|
||||||
|
LICENSE
|
||||||
|
dockerfile
|
||||||
|
.dockerignore
|
||||||
|
README.md
|
||||||
@@ -20,15 +20,6 @@ jobs:
|
|||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
driver-opts: |
|
driver-opts: |
|
||||||
image=moby/buildkit:latest
|
image=moby/buildkit:latest
|
||||||
network=host
|
|
||||||
|
|
||||||
- name: Cache Docker layers
|
|
||||||
uses: actions/cache@v3
|
|
||||||
with:
|
|
||||||
path: /tmp/.buildx-cache
|
|
||||||
key: ${{ runner.os }}-buildx-${{ github.sha }}
|
|
||||||
restore-keys: |
|
|
||||||
${{ runner.os }}-buildx-
|
|
||||||
|
|
||||||
- name: Log in to registry
|
- name: Log in to registry
|
||||||
uses: docker/login-action@v2
|
uses: docker/login-action@v2
|
||||||
@@ -43,13 +34,8 @@ jobs:
|
|||||||
context: .
|
context: .
|
||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
push: true
|
push: true
|
||||||
cache-from: type=local,src=/tmp/.buildx-cache
|
cache-from: type=registry,ref=${{ vars.REGISTRY }}/${{ github.repository_owner }}/${{ vars.IMAGE_NAME }}:cache
|
||||||
cache-to: type=local,dest=/tmp/.buildx-cache-new,mode=max
|
cache-to: type=registry,ref=${{ vars.REGISTRY }}/${{ github.repository_owner }}/${{ vars.IMAGE_NAME }}:cache,mode=max
|
||||||
tags: |
|
tags: |
|
||||||
${{ vars.REGISTRY }}/${{ github.repository_owner }}/${{ vars.IMAGE_NAME }}:latest
|
${{ vars.REGISTRY }}/${{ github.repository_owner }}/${{ vars.IMAGE_NAME }}:latest
|
||||||
${{ vars.REGISTRY }}/${{ github.repository_owner }}/${{ vars.IMAGE_NAME }}:${{ github.sha }}
|
${{ vars.REGISTRY }}/${{ github.repository_owner }}/${{ vars.IMAGE_NAME }}:${{ github.sha }}
|
||||||
|
|
||||||
- name: Move cache
|
|
||||||
run: |
|
|
||||||
rm -rf /tmp/.buildx-cache
|
|
||||||
mv /tmp/.buildx-cache-new /tmp/.buildx-cache
|
|
||||||
42
dockerfile
42
dockerfile
@@ -1,23 +1,36 @@
|
|||||||
# Use official Python image
|
# Use official Python image
|
||||||
FROM python:3.11-slim
|
FROM python:3.11-slim as builder
|
||||||
|
|
||||||
# Set working directory
|
# Install system dependencies for building
|
||||||
WORKDIR /app
|
|
||||||
|
|
||||||
# Install dependencies
|
|
||||||
RUN apt-get update && apt-get install -y \
|
RUN apt-get update && apt-get install -y \
|
||||||
gcc \
|
gcc \
|
||||||
python3-dev \
|
python3-dev \
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
# Install tini for better signal handling in container
|
# Create virtual environment
|
||||||
RUN apt-get update && apt-get install -y tini
|
RUN python -m venv /opt/venv
|
||||||
|
ENV PATH="/opt/venv/bin:$PATH"
|
||||||
|
|
||||||
# Copy requirements first to leverage Docker cache
|
# Copy requirements first to leverage Docker cache
|
||||||
COPY requirements.txt .
|
COPY requirements.txt .
|
||||||
|
|
||||||
# Install Python dependencies
|
# Install Python dependencies with cache dir
|
||||||
RUN pip install --no-cache-dir -r requirements.txt
|
RUN --mount=type=cache,target=/root/.cache/pip \
|
||||||
|
pip install --no-cache-dir -r requirements.txt
|
||||||
|
|
||||||
|
# Final stage
|
||||||
|
FROM python:3.11-slim
|
||||||
|
|
||||||
|
# Set working directory
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Install tini for better signal handling in container
|
||||||
|
RUN apt-get update && apt-get install -y tini && \
|
||||||
|
rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Copy virtual environment from builder
|
||||||
|
COPY --from=builder /opt/venv /opt/venv
|
||||||
|
ENV PATH="/opt/venv/bin:$PATH"
|
||||||
|
|
||||||
# Create a non-root user
|
# Create a non-root user
|
||||||
RUN groupadd -r bot && useradd -r -g bot bot
|
RUN groupadd -r bot && useradd -r -g bot bot
|
||||||
@@ -26,14 +39,9 @@ RUN groupadd -r bot && useradd -r -g bot bot
|
|||||||
COPY --chown=bot:bot . .
|
COPY --chown=bot:bot . .
|
||||||
|
|
||||||
# Create directories for persistent storage and modify permissions
|
# Create directories for persistent storage and modify permissions
|
||||||
RUN chown -R bot:bot /app && \
|
RUN mkdir -p logs embed && \
|
||||||
chmod -R 777 /app
|
chown -R bot:bot /app logs embed && \
|
||||||
RUN mkdir -p logs && \
|
chmod -R 777 /app logs embed
|
||||||
chown -R bot:bot logs && \
|
|
||||||
chmod -R 777 logs && \
|
|
||||||
mkdir -p embed && \
|
|
||||||
chown -R bot:bot embed && \
|
|
||||||
chmod -R 777 embed
|
|
||||||
|
|
||||||
# Switch to non root user
|
# Switch to non root user
|
||||||
USER bot
|
USER bot
|
||||||
|
|||||||
Reference in New Issue
Block a user