The build context is the repository root and there was no .dockerignore, so
'COPY backend/ ./' swept backend/venv (327 MB), backend/media (the actual
library, 224 MB), backend/logs, backend/staticfiles and backend/.env
(SECRET_KEY plus the database password) into the backend image: 1.43 GB per
architecture, including secrets headed for the registry. The frontend build
stage also copied the host's node_modules over the fresh install.
- Root .dockerignore excludes .git, virtualenvs, __pycache__, db.sqlite3,
logs/staticfiles, .env files, media/, node_modules, dist and the deploy
runtime state (data/, tailscale-state/).
- The backend Dockerfile now asserts the context is clean (.env, venv,
media/library, db.sqlite3 all absent) before collectstatic, so a missing
ignore file fails the build instead of leaking.
- Rebuilt: backend 1.43 GB -> 876 MB ('COPY backend/' is now 268 kB),
frontend stays at 65 MB. Verified by booting the compose stack with the
new image: migrations applied, /health ok, no .env or venv inside, and
/app/media is the mounted (empty) volume; the scheduler runs too.
- Removed the stale local images that still contained the library and the
dev .env.
50 lines
1.6 KiB
Plaintext
50 lines
1.6 KiB
Plaintext
# J621-Backend — Django + gunicorn, with migrations applied on start.
|
|
#
|
|
# Build context is the repository root, e.g.:
|
|
# docker build -f deploy/J621-Backend -t j621-backend .
|
|
#
|
|
# Needs MariaDB and Redis (see the compose files). ffmpeg is used for video
|
|
# thumbnails; media/logs live under the mounted volumes.
|
|
|
|
# syntax=docker/dockerfile:1
|
|
|
|
FROM python:3.14-slim
|
|
|
|
# Baked in by the push scripts so the shell's version pill shows the commit
|
|
# even though the image has no .git directory.
|
|
ARG GIT_HASH=unknown
|
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
|
PYTHONUNBUFFERED=1 \
|
|
GIT_COMMIT_HASH=$GIT_HASH
|
|
|
|
WORKDIR /app
|
|
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends ffmpeg \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
COPY backend/requirements.txt ./
|
|
RUN pip install --no-cache-dir -r requirements.txt
|
|
|
|
COPY backend/ ./
|
|
COPY deploy/backend-entrypoint.sh /usr/local/bin/j621-entrypoint
|
|
COPY deploy/scheduler-entrypoint.sh /usr/local/bin/j621-scheduler
|
|
|
|
# Guard: fail the build if the context leaked secrets or runtime data
|
|
# (.dockerignore excludes them — see the repository root).
|
|
RUN test ! -e /app/.env \
|
|
&& test ! -d /app/venv \
|
|
&& test ! -d /app/media/library \
|
|
&& test ! -e /app/db.sqlite3 \
|
|
&& echo "build context clean"
|
|
|
|
RUN chmod +x /usr/local/bin/j621-entrypoint /usr/local/bin/j621-scheduler \
|
|
&& mkdir -p /app/media /app/logs \
|
|
&& python manage.py collectstatic --noinput
|
|
|
|
EXPOSE 8000
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s \
|
|
CMD python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health')" || exit 1
|
|
|
|
ENTRYPOINT ["j621-entrypoint"]
|