Skip to content

Commit

Permalink
Update Dockerfile and remove AWS AK/SAK
Browse files Browse the repository at this point in the history
  • Loading branch information
bhvishal9 committed Aug 20, 2024
1 parent 0b2b95c commit 4f4d9c2
Show file tree
Hide file tree
Showing 6 changed files with 258 additions and 44 deletions.
176 changes: 176 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,176 @@
### Python template
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class

# C extensions
*.so

# Distribution / packaging
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST

# PyInstaller
# Usually these files are written by a python script from a template
# before PyInstaller builds the exe, so as to inject date/other infos into it.
*.manifest
*.spec

# Installer logs
pip-log.txt
pip-delete-this-directory.txt

# Unit test / coverage reports
htmlcov/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/
cover/

# Translations
*.mo
*.pot

# Django stuff:
*.log
local_settings.py
db.sqlite3
db.sqlite3-journal

# Flask stuff:
instance/
.webassets-cache

# Scrapy stuff:
.scrapy

# Sphinx documentation
docs/_build/

# PyBuilder
.pybuilder/
target/

# Jupyter Notebook
.ipynb_checkpoints

# IPython
profile_default/
ipython_config.py

# pyenv
# For a library or package, you might want to ignore these files since the code is
# intended to run in multiple environments; otherwise, check them in:
# .python-version

# pipenv
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
# However, in case of collaboration, if having platform-specific dependencies or dependencies
# having no cross-platform support, pipenv may install dependencies that don't work, or not
# install all needed dependencies.
#Pipfile.lock

# poetry
# Similar to Pipfile.lock, it is generally recommended to include poetry.lock in version control.
# This is especially recommended for binary packages to ensure reproducibility, and is more
# commonly ignored for libraries.
# https://python-poetry.org/docs/basic-usage/#commit-your-poetrylock-file-to-version-control
#poetry.lock

# pdm
# Similar to Pipfile.lock, it is generally recommended to include pdm.lock in version control.
#pdm.lock
# pdm stores project-wide configurations in .pdm.toml, but it is recommended to not include it
# in version control.
# https://pdm.fming.dev/#use-with-ide
.pdm.toml

# PEP 582; used by e.g. github.com/David-OConnor/pyflow and github.com/pdm-project/pdm
__pypackages__/

# Celery stuff
celerybeat-schedule
celerybeat.pid

# SageMath parsed files
*.sage.py

# Environments
.env
.venv
env/
venv/
ENV/
env.bak/
venv.bak/

# Spyder project settings
.spyderproject
.spyproject

# Rope project settings
.ropeproject

# mkdocs documentation
/site

# mypy
.mypy_cache/
.dmypy.json
dmypy.json

# Pyre type checker
.pyre/

# pytype static type analyzer
.pytype/

# Cython debug symbols
cython_debug/

# PyCharm
# JetBrains specific template is maintained in a separate JetBrains.gitignore that can
# be found at https://github.com/github/gitignore/blob/main/Global/JetBrains.gitignore
# and can be added to the global gitignore or merged into this file. For a more nuclear
# option (not recommended) you can uncomment the following to ignore the entire idea folder.
.idea/

# Other files
heroku.yml
docker-compose.yml
.pre-commit-config.yaml
.vscode/
.gitignore
.github/
.devcontainer/
.env.example
LICENSE
README.md
Dockerfile
.dockerignore
.git/
26 changes: 16 additions & 10 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,15 @@
name: ci
on: push

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read
id-token: write
packages: read

jobs:
lint:
name: Lint
Expand All @@ -18,18 +27,15 @@ jobs:
env:
PORT: "8000"
S3_BUCKET: "-"
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
S3_TEST_BUCKET: ${{ secrets.S3_TEST_BUCKET }}
S3_TEST_BUCKET: "kittl-uploads-storage-staging"
steps:
- name: Check out repository code
uses: actions/checkout@v2
- name: Checkout
uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v1
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: eu-central-1
aws-region: 'eu-central-1'
role-to-assume: 'arn:aws:iam::339713006905:role/vectorizing-github-actions'
- name: Set up Python 3.11
uses: actions/setup-python@v2
with:
Expand All @@ -47,4 +53,4 @@ jobs:
shell: bash -el {0}
run: |
conda activate dev
python -m pytest vectorizing/tests/test.py
python -m pytest vectorizing/tests/test.py
3 changes: 2 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -11,4 +11,5 @@ htmlcov/
dist/
build/
*.egg-info/
diff_output
diff_output
.idea/
53 changes: 44 additions & 9 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,10 +1,45 @@
FROM python:3.11
RUN apt-get update -y
RUN apt-get install wget build-essential python3-dev libagg-dev libpotrace-dev pkg-config libgl1 -y

WORKDIR /
COPY requirements/dev.txt /
RUN pip install -r dev.txt
COPY . /
# Use an official Python runtime as a parent image
FROM python:3.11-slim

# Install necessary packages
RUN apt-get update -y && apt-get install -y \
wget \
build-essential \
python3-dev \
libagg-dev \
libpotrace-dev \
pkg-config \
libgl1 \
--no-install-recommends && \
rm -rf /var/lib/apt/lists/*

# Create a non-root user and group with specific IDs for consistency
RUN addgroup --gid 1001 appuser && \
adduser --uid 1001 --gid 1001 --disabled-password --gecos "" appuser

# Set the working directory
WORKDIR /app

# Copy only requirements to leverage Docker cache
COPY requirements/dev.txt /app/requirements.txt

# Install Python dependencies
RUN pip install --no-cache-dir -r /app/requirements.txt

# Copy the rest of the application code
COPY . /app

# Change ownership of the application files
RUN chown -R appuser:appuser /app

# Switch to the non-root user
USER appuser

# Set environment variables
ENV PORT=5000
CMD gunicorn -w 4 'vectorizing:create_app()' --timeout 0 -b 0.0.0.0:$PORT

# Expose the port
EXPOSE $PORT

# Define the command to run the application
CMD ["gunicorn", "-w", "4", "vectorizing:create_app()", "--timeout", "0", "-b", "0.0.0.0:5000"]
Loading

0 comments on commit 4f4d9c2

Please sign in to comment.