Files
bambuddy/Dockerfile
T
maziggy 2722ed1538 Bake .git/HEAD into Docker image so branch detection actually works
The SpoolBuddy remote-update flow always pulled `main` on the remote
  device when Bambuddy ran under Docker, regardless of which branch the
  image was built from. Root cause: the Dockerfile COPYs only backend/
  and static/, and .dockerignore excluded .git entirely, so the container
  had no git metadata anywhere. detect_current_branch() silently fell
  through its file-read path and returned the GIT_BRANCH env-var default
  of "main".

  The old subprocess-based implementation had the same bug but it was
  masked twice: no .git in the image AND no `git` binary in the image,
  so git rev-parse raised FileNotFoundError, the bare except swallowed
  it, and the fallback kicked in.

  Let the one file we actually need (.git/HEAD — ~20 bytes containing
  `ref: refs/heads/<branch>`) through the .dockerignore filter and COPY
  it into the image at /app/.git/HEAD. detect_current_branch() already
  reads exactly that path, so no Python code changes are needed. Bind-
  mount development setups are unaffected — the bind mount overlays the
  baked-in file with the live repo's .git/HEAD.

  Verified with a throwaway alpine build using the same .dockerignore
  pattern: .git/HEAD passes through, decoy .git/refs and .git/objects
  entries are excluded, and COPY writes the expected content into the
  image.
2026-04-10 11:11:39 +02:00

94 lines
3.2 KiB
Docker

# Build frontend
FROM node:22-bookworm-slim AS frontend-builder
WORKDIR /app/frontend
# Copy package files first for better caching
COPY frontend/package*.json ./
# Use cache mount for npm
RUN --mount=type=cache,target=/root/.npm \
npm ci
COPY frontend/ ./
RUN npm run build
# Production image
FROM python:3.13-slim
WORKDIR /app
# Install system dependencies
ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
ffmpeg \
iproute2 \
libcap2-bin \
openssh-client \
&& rm -rf /var/lib/apt/lists/*
# Allow binding to privileged ports (e.g. 990/FTPS) as non-root user.
# File capabilities are more reliable than Docker cap_add with user: directive,
# which depends on ambient capability support in the container runtime.
RUN setcap cap_net_bind_service=+ep "$(readlink -f /usr/local/bin/python3)"
# Install Python dependencies with cache mount
COPY requirements.txt ./
RUN --mount=type=cache,target=/root/.cache/pip \
pip install --root-user-action=ignore -r requirements.txt
# Copy backend
COPY backend/ ./backend/
# Capture the current git branch at build time. `.git/HEAD` is the only
# .git metadata the build context lets through (see .dockerignore); it
# contains `ref: refs/heads/<branch>`, which the SpoolBuddy remote-update
# flow reads at runtime via detect_current_branch() in spoolbuddy_ssh.py.
# Without this, the production image has no git metadata at all and would
# always pull `main` on the remote device regardless of which branch
# Bambuddy itself was built from.
COPY .git/HEAD ./.git/HEAD
# Copy built frontend from builder stage
COPY --from=frontend-builder /app/static ./static
# Create data directory for persistent storage
# chmod 777 allows running as non-root user (e.g., with docker compose user: directive)
RUN mkdir -p /app/data /app/logs && chmod 777 /app/data /app/logs
# Environment variables
ENV PYTHONUNBUFFERED=1
ENV DATA_DIR=/app/data
ENV LOG_DIR=/app/logs
ENV PORT=8000
# Provide a local username + home for tools that call getpass.getuser() /
# os.path.expanduser() under arbitrary PUIDs. With `user: "1001:1001"` the
# stock python:3.13-slim image has no /etc/passwd entry for that UID, so
# pwd.getpwuid() raises and breaks libraries that do host-level user lookups
# (notably asyncssh, which uses the local username for ~/.ssh/config host
# matching during the SpoolBuddy remote-update flow). Setting LOGNAME/USER
# makes getpass.getuser() resolve via env vars instead of the passwd db;
# HOME=/app gives a writable home that is guaranteed to exist.
ENV HOME=/app
ENV USER=bambuddy
ENV LOGNAME=bambuddy
EXPOSE 322
EXPOSE 990
EXPOSE 3000
EXPOSE 3002
EXPOSE 6000
EXPOSE 8000
EXPOSE 8883
EXPOSE 50000-50100
# Health check (uses PORT env var via shell)
HEALTHCHECK --interval=30s --timeout=10s --start-period=10s --retries=3 \
CMD python -c "import urllib.request, os; urllib.request.urlopen(f'http://localhost:{os.environ.get(\"PORT\", \"8000\")}/health')" || exit 1
# Run the application
# Use standard asyncio loop (uvloop has permission issues in some Docker environments)
# Port is configurable via PORT environment variable (default: 8000)
CMD ["sh", "-c", "uvicorn backend.app.main:app --host 0.0.0.0 --port ${PORT:-8000} --loop asyncio"]