booleanbeyond/jobfetch
0
1# Playwright's image already carries Chromium and every system library it2# needs, which is the fiddly part of shipping a headless browser.3FROM mcr.microsoft.com/playwright/python:v1.47.0-jammy4 5ENV PYTHONUNBUFFERED=1 \6 PYTHONDONTWRITEBYTECODE=1 \7 PIP_NO_CACHE_DIR=18 9# Install browsers to the base image's shared location rather than root's cache,10# so the unprivileged runtime user can still read them.11ENV PLAYWRIGHT_BROWSERS_PATH=/ms-playwright12 13WORKDIR /srv14 15COPY requirements.txt .16RUN pip install --no-cache-dir -r requirements.txt \17 && python -m playwright install chromium18 19COPY app ./app20COPY static ./static21 22# Run unprivileged: this process fetches attacker-influenced URLs.23#24# UID 1000 specifically: Hugging Face Spaces runs every container as UID 100025# and files owned by anyone else are unreadable there. The Playwright base image26# may already have a user on that ID, so reuse it instead of failing the build27# on a duplicate. Group 0 plus g+rwX keeps it working on OpenShift-style hosts28# that assign an arbitrary UID but always keep GID 0.29RUN if ! id -u 1000 >/dev/null 2>&1; then \30 useradd --create-home --uid 1000 jobfetch; \31 fi \32 && mkdir -p /home/appuser \33 && chown -R 1000:0 /srv /home/appuser \34 && chmod -R g+rwX /srv /home/appuser35USER 100036 37# Chromium needs a writable HOME for its profile directory and crash dumps; with38# an unwritable one it fails to launch at all as a non-root user.39ENV HOME=/home/appuser40 41EXPOSE 800042HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \43 CMD python -c "import os,urllib.request,sys; p=os.getenv('PORT','8000'); sys.exit(0 if urllib.request.urlopen(f'http://127.0.0.1:{p}/healthz',timeout=4).status==200 else 1)"44 45# Render, Cloud Run and Railway inject $PORT and route traffic only there, so a46# hardcoded port fails their health check and never receives requests. `exec`47# keeps uvicorn as PID 1 so SIGTERM still reaches it and shutdown stays graceful.48CMD ["sh", "-c", "exec uvicorn app.main:app --host 0.0.0.0 --port ${PORT:-8000} --workers 1"]49 