Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
# Version control
.git
.gitignore

# Python caches and virtualenvs
__pycache__/
*.py[cod]
*.egg-info/
.eggs/
.pytest_cache/
.ruff_cache/
.mypy_cache/
.coverage
htmlcov/
pythonie-venv/
.venv/
venv/

# Local databases and media
*.sqlite3
pythonie/db.sqlite3
media/

# Secrets and local env
.env
.envrc
*.env

# Editor / OS noise
.vscode/
.idea/
.DS_Store

# Worktrees and tooling output
.claude/
graphify-out/

# Docs and CI not needed in the build context
*.md
.github/
55 changes: 44 additions & 11 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,15 +1,48 @@
# syntax=docker/dockerfile:1.21.0
FROM python:3.13 AS compile-stage
RUN --mount=type=cache,target=/var/cache/apt \
apt update && \
apt install -y --no-install-recommends \
build-essential gcc neovim fish less iputils-ping postgresql-client \
ack
ADD pyproject.toml uv.lock ./
RUN --mount=type=cache,target=/root/.cache \
pip install -U pip uv && \

# ---- builder: install Python deps into an isolated venv via uv ----
FROM python:3.13-slim AS builder

COPY --from=ghcr.io/astral-sh/uv:0.12.1 /uv /uvx /usr/local/bin/

ENV UV_LINK_MODE=copy \
UV_PROJECT_ENVIRONMENT=/opt/venv \
UV_PYTHON_DOWNLOADS=never \
PIP_DISABLE_PIP_VERSION_CHECK=1

# build-essential/gcc are only needed to build wheels that lack a prebuilt one.
# They live in this stage only and never reach the final image.
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \
--mount=type=cache,target=/var/lib/apt/lists,sharing=locked \
apt-get update && \
apt-get install -y --no-install-recommends \
build-essential gcc

WORKDIR /app

COPY pyproject.toml uv.lock ./

# Install everything into a self-contained venv at /opt/venv so the final
# stage can copy it without dragging in the build toolchain.
RUN --mount=type=cache,target=/root/.cache/uv \
uv sync --frozen --all-groups
ENV PATH="/.venv/bin:$PATH"

FROM compile-stage AS tests-stage
# ---- dev: lean runtime image with interactive tooling (used by web + test) ----
FROM python:3.13-slim AS dev

ENV PATH="/opt/venv/bin:$PATH" \
PYTHONUNBUFFERED=1 \
PYTHONDONTWRITEBYTECODE=1

# Runtime-only system packages: the postgres client for psql/pg_dump plus the
# interactive tooling the dev shell relies on (compose runs `fish`).
RUN --mount=type=cache,target=/var/cache/apt,sharing=locked \
--mount=type=cache,target=/var/lib/apt/lists,sharing=locked \
apt-get update && \
apt-get install -y --no-install-recommends \
postgresql-client \
fish neovim less ack iputils-ping

COPY --from=builder /opt/venv /opt/venv

WORKDIR /app
5 changes: 5 additions & 0 deletions Taskfile.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,11 @@ tasks:
cmds:
- docker build --no-cache -t $DOCKER_IMAGE .

docker:build:cached:
desc: Build the docker image reusing the build cache (faster rebuilds)
cmds:
- docker build -t $DOCKER_IMAGE .

docker:run:
desc: Run a shell into the docker container
cmds:
Expand Down
Loading