# Usage: # make build # Build all Docker images (admin + worker) # docker compose up -d # Start all services # # - admin stage: python:3.11-slim (FastAPI only, no Chrome) # - worker stage: Playwright Noble with Python + Chromium pre-installed # from your local registry mirror. # ── Build args ───────────────────────────────────────────────────────────────── ARG BASE_IMAGE=python:3.11-slim # ── Stage 1: dependency resolver ───────────────────────────────────────────── FROM python:3.11-slim AS builder WORKDIR /app # python:3.11-slim has neither curl nor pip. Bootstrap pip via ensurepip, # then use it to install uv from the local PyPI mirror. RUN python -m ensurepip --upgrade \ && python -m pip install --break-system-packages \ --index-url https://pypi.reg.darano.ir/simple/ \ --trusted-host pypi.reg.darano.ir \ uv ENV PATH="/usr/local/bin:$PATH" \ UV_DEFAULT_INDEX="https://pypi.reg.darano.ir" COPY pyproject.toml uv.lock* ./ RUN uv sync --frozen --no-dev --no-install-project # ── Stage 2a: admin runtime (python:3.11-slim, no Chrome needed) ────────────── FROM ${BASE_IMAGE} AS admin WORKDIR /app ENV PATH="/app/.venv/bin:$PATH" \ PYTHONUNBUFFERED=1 \ PYTHONDONTWRITEBYTECODE=1 \ UV_DEFAULT_INDEX="https://pypi.reg.darano.ir" COPY . . COPY --from=builder /app/.venv /app/.venv RUN mkdir -p data logs recordings \ && useradd -m -u 1001 seed \ && chown -R seed:seed /app USER seed EXPOSE 8000 CMD ["python", "main.py", "admin"] # ── Stage 2b: worker runtime (Playwright Noble + Python installed) ───────────── # Base: oci.reg.darano.ir/mcr.microsoft.com/playwright:v1.62.0-noble # This image ships: Ubuntu 24.04 + Chromium + Firefox + WebKit + system libs. # We add Python + uv ourselves. FROM oci.reg.darano.ir/mcr.microsoft.com/playwright:v1.62.0-noble AS worker # Install Python 3.12 + uv, then sync deps — all in one RUN. # Use a mirror for apt since the VPS has network restrictions (Iran). RUN printf 'Types: deb\nURIs: http://repo.iut.ac.ir/ubuntu/\nSuites: noble noble-updates noble-security\nComponents: main restricted universe multiverse\nSigned-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg\n' \ > /etc/apt/sources.list.d/ubuntu.sources \ && apt-get update && apt-get install -y --no-install-recommends \ python3 python3-venv \ && rm -rf /var/lib/apt/lists/* \ && curl -LsSf https://astral.sh/uv/install.sh | sh \ && ln -sf /usr/local/bin/uv /usr/local/bin/uv ENV PATH="/root/.local/bin:$PATH" \ UV_DEFAULT_INDEX="https://pypi.reg.darano.ir" \ # Chromium is pre-installed at /usr/bin/chromium CHROME_BINARY=/usr/bin/chromium \ CHROMEDRIVER_PATH=/usr/bin/chromedriver \ HEADLESS=true WORKDIR /app # Copy manifests first (stable cache layer) COPY pyproject.toml uv.lock* ./ # Install project deps into a venv targeting this image's Python 3.12 RUN uv sync --frozen --no-dev --no-install-project # Copy app code COPY . . # mkdir for volumes, user for security RUN mkdir -p data logs recordings \ && useradd -m -u 1001 seed 2>/dev/null || true \ && chown -R seed:seed /app 2>/dev/null || true USER seed # CMD overridden in docker-compose.yml to use RQ worker CMD ["rq", "worker", "--url", "redis://redis:6379/0", "batch"]