# syntax=docker/dockerfile:1 # Stage 1: Build Vue frontend FROM node:22-alpine AS build-frontend WORKDIR /build COPY frontend/package.json frontend/package-lock.json* ./ RUN npm ci --quiet COPY frontend/ . RUN npm run build # Stage 2: Python runtime # Tracks CI image (ci-python:3.14) so test results stay representative. FROM python:3.14-slim AS runtime WORKDIR /app # Installed from uv.lock, exactly like CI (issue #2194). This used to be # `COPY pyproject.toml .` + `pip install .`, which never even copied the lock: # the shipped image resolved its own dependency set, so CI could be green on one # set of versions while the published image ran another. On 2026-07-28 that # class of drift turned `main` red when mcp 2.0.0 shipped mid-session. RUN --mount=type=cache,target=/root/.cache/pip \ pip install --no-cache-dir uv # Dependencies before source, so the expensive layer is cached on every build # that doesn't change the lock. COPY pyproject.toml uv.lock ./ RUN --mount=type=cache,target=/root/.cache/uv \ uv sync --locked --no-dev --no-install-project COPY src/ src/ RUN --mount=type=cache,target=/root/.cache/uv \ uv sync --locked --no-dev # uv sync installs into a project venv rather than the system interpreter, so # alembic and hypercorn in CMD have to be found there. ENV PATH="/app/.venv/bin:$PATH" COPY --from=build-frontend /build/dist/ src/scribe/static/ COPY alembic.ini . COPY alembic/ alembic/ # Ensure Python finds the source tree (where static files live) before site-packages ENV PYTHONPATH=/app/src # Version is injected at build time via --build-arg BUILD_VERSION=YY.MM.DD.N # Falls back to "dev" for local / untagged builds ARG BUILD_VERSION=dev ENV APP_VERSION=$BUILD_VERSION EXPOSE 5000 CMD ["sh", "-c", "alembic upgrade head && hypercorn 'scribe.app:create_app()' --bind 0.0.0.0:5000 --keep-alive 600"]