1b81310847
CI & Build / Python lint (push) Successful in 4s
CI & Build / TypeScript typecheck (push) Successful in 12s
CI & Build / integration (push) Successful in 17s
CI & Build / Python tests (push) Successful in 44s
CI & Build / Build & push image (push) Successful in 40s
The other half of #2194. The runtime stage did `COPY pyproject.toml .` + `pip install .` and never copied uv.lock at all, so the SHIPPED IMAGE resolved its own dependency set — independently of CI and of the lock. CI could be green on one set of versions while the published image ran another, which makes a green run evidence about the tests and not about the artifact. Now: install uv, sync deps from the lock, then sync the project. Split into two syncs so the dependency layer caches on any build that doesn't touch the lock — the same shape CI uses, so image and CI can no longer disagree. `uv sync` installs into /app/.venv rather than the system interpreter, so PATH picks it up for the alembic + hypercorn CMD. The project stays editable, which keeps /app/src authoritative exactly as PYTHONPATH and the frontend-dist copy into src/scribe/static/ already assume. Not built locally (rules #10/#12) — the dev build job verifies it, and `main` already carries a working :latest, so a break here can't strand a deploy.
51 lines
1.8 KiB
Docker
51 lines
1.8 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Stage 1: Build Vue frontend
|
|
FROM node:22-alpine AS build-frontend
|
|
WORKDIR /build
|
|
COPY frontend/package.json frontend/package-lock.json* ./
|
|
RUN npm ci --quiet
|
|
COPY frontend/ .
|
|
RUN npm run build
|
|
|
|
# Stage 2: Python runtime
|
|
# Tracks CI image (ci-python:3.14) so test results stay representative.
|
|
FROM python:3.14-slim AS runtime
|
|
WORKDIR /app
|
|
|
|
# Installed from uv.lock, exactly like CI (issue #2194). This used to be
|
|
# `COPY pyproject.toml .` + `pip install .`, which never even copied the lock:
|
|
# the shipped image resolved its own dependency set, so CI could be green on one
|
|
# set of versions while the published image ran another. On 2026-07-28 that
|
|
# class of drift turned `main` red when mcp 2.0.0 shipped mid-session.
|
|
RUN --mount=type=cache,target=/root/.cache/pip \
|
|
pip install --no-cache-dir uv
|
|
|
|
# Dependencies before source, so the expensive layer is cached on every build
|
|
# that doesn't change the lock.
|
|
COPY pyproject.toml uv.lock ./
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --locked --no-dev --no-install-project
|
|
|
|
COPY src/ src/
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --locked --no-dev
|
|
|
|
# uv sync installs into a project venv rather than the system interpreter, so
|
|
# alembic and hypercorn in CMD have to be found there.
|
|
ENV PATH="/app/.venv/bin:$PATH"
|
|
|
|
COPY --from=build-frontend /build/dist/ src/scribe/static/
|
|
COPY alembic.ini .
|
|
COPY alembic/ alembic/
|
|
|
|
# Ensure Python finds the source tree (where static files live) before site-packages
|
|
ENV PYTHONPATH=/app/src
|
|
|
|
# Version is injected at build time via --build-arg BUILD_VERSION=YY.MM.DD.N
|
|
# Falls back to "dev" for local / untagged builds
|
|
ARG BUILD_VERSION=dev
|
|
ENV APP_VERSION=$BUILD_VERSION
|
|
|
|
EXPOSE 5000
|
|
CMD ["sh", "-c", "alembic upgrade head && hypercorn 'scribe.app:create_app()' --bind 0.0.0.0:5000 --keep-alive 600"]
|