# J621-Backend — Django + gunicorn, with migrations applied on start. # # Build context is the repository root, e.g.: # docker build -f deploy/J621-Backend -t j621-backend . # # Needs MariaDB and Redis (see the compose files). ffmpeg is used for video # thumbnails; media/logs live under the mounted volumes. # syntax=docker/dockerfile:1 FROM python:3.14-slim # Baked in by the push scripts so the shell's version pill shows the commit # even though the image has no .git directory. ARG GIT_HASH=unknown ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 \ GIT_COMMIT_HASH=$GIT_HASH WORKDIR /app RUN apt-get update \ && apt-get install -y --no-install-recommends ffmpeg \ && rm -rf /var/lib/apt/lists/* COPY backend/requirements.txt ./ RUN pip install --no-cache-dir -r requirements.txt COPY backend/ ./ COPY deploy/backend-entrypoint.sh /usr/local/bin/j621-entrypoint COPY deploy/scheduler-entrypoint.sh /usr/local/bin/j621-scheduler # Guard: fail the build if the context leaked secrets or runtime data # (.dockerignore excludes them — see the repository root). RUN test ! -e /app/.env \ && test ! -d /app/venv \ && test ! -d /app/media/library \ && test ! -e /app/db.sqlite3 \ && echo "build context clean" RUN chmod +x /usr/local/bin/j621-entrypoint /usr/local/bin/j621-scheduler \ && mkdir -p /app/media /app/logs \ && python manage.py collectstatic --noinput EXPOSE 8000 HEALTHCHECK --interval=30s --timeout=5s --start-period=30s \ CMD python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health')" || exit 1 ENTRYPOINT ["j621-entrypoint"]