# --- Build/deps stage --- FROM python:3.12-slim AS builder WORKDIR /app # Install build deps only where needed, keep layer cacheable COPY requirements.txt . RUN pip install --no-cache-dir --user -r requirements.txt # --- Runtime stage --- FROM python:3.12-slim # Security: run as a non-root user (required best practice for ghaymah.systems containers) RUN useradd --create-home --shell /usr/sbin/nologin appuser WORKDIR /app COPY --from=builder /root/.local /home/appuser/.local COPY app.py . ENV PATH=/home/appuser/.local/bin:$PATH \ PYTHONUNBUFFERED=1 \ PORT=8080 RUN chown -R appuser:appuser /app USER appuser EXPOSE 8080 # Container-native healthcheck (in addition to ghaymah platform probes hitting /health) HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ CMD python -c "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:8080/health', timeout=2).status==200 else 1)" # Use gunicorn in production instead of Flask's dev server CMD ["gunicorn", "--bind", "0.0.0.0:8080", "--workers", "2", "--threads", "4", "--timeout", "30", "app:app"]