FROM python:3.9-slim # Set environment variables ENV PYTHONDONTWRITEBYTECODE=1 ENV PYTHONUNBUFFERED=1 # Set work directory WORKDIR /app # Install system dependencies RUN apt-get update \ && apt-get install -y --no-install-recommends \ build-essential \ curl \ libssl-dev \ libffi-dev \ && rm -rf /var/lib/apt/lists/* # Copy requirements and install Python dependencies COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt # Copy application code COPY src/ ./src/ # Create non-root user for security RUN adduser --disabled-password --gecos '' appuser RUN chown -R appuser:appuser /app USER appuser # Add src directory to PYTHONPATH ENV PYTHONPATH="/app/src:$PYTHONPATH" # Expose port EXPOSE 8008 # Health check HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \ CMD curl -f http://localhost:8008/health || exit 1 # Start the application from src directory WORKDIR /app/src CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8008"]