diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..6f2e1ef --- /dev/null +++ b/.dockerignore @@ -0,0 +1,8 @@ +venv +__pycache__ +*.pyc +.pytest_cache +*.log +.env +.git +tests diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..eabbd5d --- /dev/null +++ b/Dockerfile @@ -0,0 +1,25 @@ +FROM python:3.11-slim + +WORKDIR /app + +# psycopg[binary] avoids needing libpq-dev; sentence-transformers/scikit-learn/ +# scipy all ship prebuilt wheels for this image, so no extra build toolchain +# is needed. Playwright's Python package installs, but its browser binary is +# NOT installed here - it's only a last-resort image-search fallback +# (see requirements.txt); run `playwright install chromium` in the container +# if you need that specific fallback tier. +COPY requirements.txt . +RUN pip install --no-cache-dir -r requirements.txt + +COPY app ./app +COPY cli ./cli +COPY scripts ./scripts +COPY data ./data + +EXPOSE 8000 +# --proxy-headers/--forwarded-allow-ips: this container is never reached +# directly - nginx (and, in prod, Caddy) sit in front of it. Without these, +# uvicorn ignores X-Forwarded-Proto and reports every request as plain http, +# so any redirect or generated absolute URL would downgrade an https request. +CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000", \ + "--proxy-headers", "--forwarded-allow-ips", "*"]