CI / extension-version (push) Successful in 4s
CI / lint (push) Successful in 4s
Build images / sign-extension (push) Successful in 5s
Build images / build-agent (push) Successful in 7s
extension / lint (push) Successful in 18s
CI / frontend-build (push) Successful in 24s
CI / backend-lint-and-test (push) Successful in 33s
Build images / build-web (push) Successful in 1m42s
CI / integration (push) Successful in 2m11s
Build images / smoke-web (push) Successful in 57s
Build images / promote (push) Skipped
Operator, 2026-09-23: *"why isn't the healthcheck built into the image or
base on what command runs if one is passed in. why is it manually declared in
the stack here."*
No good reason. The container is the only thing that knows what it was asked
to run, and every compose file, stack file and README had to restate it:
web -> urllib /api/health
worker -> celery inspect ping -d celery@$HOSTNAME
all -> both, for every lane
Three checks written by hand, once per service, in every file anyone ever
wrote — none of them wrong until a role changed, and all of them silently
wrong after. The same duplication the lane table exists to remove one level
down, and I built it without noticing.
`entrypoint.sh` now records the role it started. The Dockerfile declares ONE
`HEALTHCHECK` that reads it and asks the right question: HTTP for web, a
self-addressed celery ping for a worker lane, both-for-every-lane for `all`,
and nothing for shell/alembic, which are one-shot and have no liveness to
probe. `docker-compose.single.yml` and the consolidated stack declare none.
A service that wants something else can still declare its own; docker prefers
it, so the escape hatch is the default docker behaviour rather than a flag.
Two details that are load-bearing:
* The role is written ONCE, by the outermost invocation. `all` starts the
other roles through this same script under supervisord, and a child
overwriting the container's role would turn the composite check into a
web-only one — silently, and only on the consolidated path. FC_ROLE is
exported so a child sees it set and skips.
* The celery ping is addressed to THIS node, not a bare ping. A bare one is
answered by any worker on the broker, so in a stack with replicas a dead
container would report healthy for as long as a sibling lived — the check
would be measuring the cluster rather than the container it is inside.
`healthcheck_all.py` is deleted; its two probes moved into the dispatcher
rather than being a second copy beside it.
An unrecorded role PASSES. The entrypoint always writes the file, so the only
way to miss it is bypassing the entrypoint — a debugging shape, where a check
that cannot tell what it is looking at must not assert the thing is broken
(snippet #3969). Said on stdout rather than assumed.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LVjrnpQjRgHdvq95rASoiR
158 lines
6.8 KiB
Docker
158 lines
6.8 KiB
Docker
# syntax=docker/dockerfile:1.25
|
|
|
|
FROM node:24-alpine AS frontend-builder
|
|
WORKDIR /build
|
|
COPY frontend/package.json frontend/package-lock.json* ./
|
|
# No package-lock.json is tracked yet (we don't run npm locally per
|
|
# feedback-no-local-runs), so `npm install` instead of `npm ci`. Flip to
|
|
# `npm ci` once a lockfile is committed.
|
|
RUN npm install --no-audit --no-fund
|
|
COPY frontend/ ./
|
|
RUN npm run build
|
|
|
|
FROM python:3.14-slim AS runtime
|
|
ENV PYTHONUNBUFFERED=1 \
|
|
PYTHONDONTWRITEBYTECODE=1 \
|
|
PIP_NO_CACHE_DIR=1 \
|
|
PIP_DISABLE_PIP_VERSION_CHECK=1
|
|
|
|
# System deps: ffmpeg (transcode + thumbnails, FC-2), unar (archives, FC-2),
|
|
# libpq for psycopg, postgresql-client + zstd for FC-5 backup/restore
|
|
# (pg_dump + tar --zstd), image libs, megatools (mega.nz public-link downloads
|
|
# for off-platform file-host links, #830 — `megatools dl`; Debian-native, no
|
|
# external MEGA apt repo needed).
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
ffmpeg \
|
|
unar \
|
|
libpq5 \
|
|
postgresql-client \
|
|
zstd \
|
|
megatools \
|
|
libjpeg62-turbo \
|
|
libwebp7 \
|
|
libpng16-16 \
|
|
ca-certificates \
|
|
# opencv-python-headless (via requirements-ml.txt) links these even in its
|
|
# headless build. Came from Dockerfile.ml when the images merged
|
|
# (milestone 422 step 6).
|
|
libgl1 \
|
|
libglib2.0-0 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
|
|
COPY requirements.txt requirements-ml.txt ./
|
|
RUN pip install -r requirements.txt
|
|
|
|
# --- ML, merged from Dockerfile.ml (milestone 422 step 6) --------------------
|
|
#
|
|
# ONE image now serves every lane. It was two because the ML lane ran in its
|
|
# own container; with the single-container layout (step 5) running every lane
|
|
# in one process tree, a second image would mean the `ml` lane could never be
|
|
# enabled from the UI — there would be no worker in this container to enable.
|
|
#
|
|
# THE COST, MEASURED from run 7273 rather than guessed — and it is far
|
|
# smaller than the estimate this comment first carried, which said "everyone
|
|
# pulls ~4GB":
|
|
#
|
|
# torch 2.12.1+cpu wheel 192.3 MB
|
|
# torchvision 0.27.1+cpu 1.8 MB
|
|
# transformers / onnxruntime / opencv / sklearn and friends
|
|
# 62.0, 35.3, 23.6, 16.7, 12.3, 9.2, 6.9 MB
|
|
# largest newly-pushed layer 222.07 MB
|
|
#
|
|
# So the ML code adds a few hundred MB to the pull, not gigabytes. The CPU
|
|
# index is what makes that true: the default PyPI torch wheel bundles the
|
|
# NVIDIA CUDA runtime and is ~2GB on its own.
|
|
#
|
|
# The GIGABYTES are in the MODEL — ~3.5GB of SigLIP weights — and those are
|
|
# NOT in this image. They arrive only when the operator enables the lane,
|
|
# which is what lets rule 164 permit a runtime fetch at all ("optional and
|
|
# clearly off"). That also settles the trade this step was asked to weigh:
|
|
# baking the weights in would add ~3.5GB to every pull for a feature many
|
|
# adopters never enable, against ~350MB for the code that makes the switch
|
|
# available. Off-by-default wins by an order of magnitude, which was NOT
|
|
# obvious before measuring — the estimate had the two costs within 15% of
|
|
# each other.
|
|
#
|
|
# `--index-url`, not `--extra-index-url`: the latter would let pip resolve a
|
|
# +cu wheel anyway, and the whole saving above depends on it not doing that.
|
|
#
|
|
# CPU-only torch from the PyTorch CPU index. Nothing here uses a GPU — the
|
|
# GPU agent is a separate service with its own image.
|
|
RUN pip install --index-url https://download.pytorch.org/whl/cpu \
|
|
"torch>=2.12,<3.0" "torchvision>=0.27,<0.28"
|
|
RUN pip install -r requirements-ml.txt
|
|
|
|
# Where the model lands. Deliberately NOT a VOLUME instruction: that mints an
|
|
# anonymous volume when nobody mounts one, which survives `docker rm` and
|
|
# accumulates 3.5GB copies nobody can find. The compose files mount it
|
|
# explicitly instead, so an unmounted run simply re-downloads — visible, and
|
|
# recoverable.
|
|
ENV HF_HOME=/models/.huggingface \
|
|
TRANSFORMERS_CACHE=/models/.huggingface \
|
|
ML_MODEL_DIR=/models
|
|
|
|
COPY backend/ ./backend/
|
|
COPY alembic/ ./alembic/
|
|
COPY alembic.ini ./
|
|
COPY entrypoint.sh ./
|
|
RUN chmod +x entrypoint.sh
|
|
|
|
COPY --from=frontend-builder /build/dist ./frontend/dist
|
|
|
|
# Which channel this image belongs to — `dev` or `main` (milestone 271 step 7).
|
|
# build.yml passes it; /api/extension/manifest reports it beside the version so
|
|
# an operator can tell which channel an install came from without the channel
|
|
# ever touching the version string.
|
|
#
|
|
# Empty by default, deliberately: a locally-built image then reports NO channel
|
|
# rather than claiming to be one, and the manifest omits the field entirely —
|
|
# indistinguishable from an image built before the field existed, which is
|
|
# exactly the shape every reader already has to handle.
|
|
#
|
|
# Declared LAST on purpose. An ARG/ENV invalidates every layer below it, and
|
|
# these are the values that differ between builds of otherwise identical
|
|
# source — put them any earlier and the two channels could never share a
|
|
# cached pip install.
|
|
#
|
|
# FC_VERSION is what the instance reports about itself in the UI. Since
|
|
# milestone 318 stopped publishing version image tags, that self-report is
|
|
# the only answer to "which build is this?" — nothing else names it.
|
|
ARG FC_CHANNEL=""
|
|
ENV FC_CHANNEL=${FC_CHANNEL}
|
|
ARG FC_VERSION=""
|
|
ENV FC_VERSION=${FC_VERSION}
|
|
|
|
EXPOSE 8080
|
|
|
|
# ONE healthcheck for every role, because the image knows which role it is
|
|
# running and a deployment should not have to repeat it. `healthcheck` reads
|
|
# the role entrypoint.sh recorded and asks the right question: HTTP for web,
|
|
# a self-addressed celery ping for a worker lane, both-for-every-lane for the
|
|
# consolidated `all`.
|
|
#
|
|
# start-period covers the SLOWEST role, which is `all`: alembic, then
|
|
# hypercorn, then four celery workers registering with the broker. A web-only
|
|
# container is ready long before this; the cost of the shared number is that
|
|
# a broken one takes a little longer to be called broken.
|
|
#
|
|
# A service may still declare its own healthcheck and docker will prefer it —
|
|
# the escape hatch for a deployment that wants something different.
|
|
HEALTHCHECK --interval=30s --timeout=15s --start-period=90s --retries=3 \
|
|
CMD ["python", "-m", "backend.app.scripts.healthcheck"]
|
|
|
|
ENTRYPOINT ["./entrypoint.sh"]
|
|
# The DEFAULT is the whole application, not one lane of it.
|
|
#
|
|
# `docker run fabledcurator` with no command starts hypercorn plus every
|
|
# worker lane under supervisord — the shape an adopter wants and the shape the
|
|
# consolidated stack runs. It was `web`, which meant the single-container
|
|
# layout only worked if you knew to ask for it by name, and a compose file
|
|
# that forgot `command:` got a web server with nothing processing its queues:
|
|
# a gallery that loads, accepts an import, and never finishes one.
|
|
#
|
|
# The multi-service stack is unaffected — every service there names its role
|
|
# explicitly, which is exactly what makes it the multi-service stack.
|
|
CMD ["all"]
|