mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
The SpoolBuddy remote-update flow always pulled `main` on the remote device when Bambuddy ran under Docker, regardless of which branch the image was built from. Root cause: the Dockerfile COPYs only backend/ and static/, and .dockerignore excluded .git entirely, so the container had no git metadata anywhere. detect_current_branch() silently fell through its file-read path and returned the GIT_BRANCH env-var default of "main". The old subprocess-based implementation had the same bug but it was masked twice: no .git in the image AND no `git` binary in the image, so git rev-parse raised FileNotFoundError, the bare except swallowed it, and the fallback kicked in. Let the one file we actually need (.git/HEAD — ~20 bytes containing `ref: refs/heads/<branch>`) through the .dockerignore filter and COPY it into the image at /app/.git/HEAD. detect_current_branch() already reads exactly that path, so no Python code changes are needed. Bind- mount development setups are unaffected — the bind mount overlays the baked-in file with the live repo's .git/HEAD. Verified with a throwaway alpine build using the same .dockerignore pattern: .git/HEAD passes through, decoy .git/refs and .git/objects entries are excluded, and COPY writes the expected content into the image.
94 lines
3.2 KiB
Docker
94 lines
3.2 KiB
Docker
# Build frontend
|
|
FROM node:22-bookworm-slim AS frontend-builder
|
|
|
|
WORKDIR /app/frontend
|
|
|
|
# Copy package files first for better caching
|
|
COPY frontend/package*.json ./
|
|
|
|
# Use cache mount for npm
|
|
RUN --mount=type=cache,target=/root/.npm \
|
|
npm ci
|
|
|
|
COPY frontend/ ./
|
|
RUN npm run build
|
|
|
|
# Production image
|
|
FROM python:3.13-slim
|
|
|
|
WORKDIR /app
|
|
|
|
# Install system dependencies
|
|
ENV DEBIAN_FRONTEND=noninteractive
|
|
RUN apt-get update && apt-get install -y --no-install-recommends \
|
|
curl \
|
|
ffmpeg \
|
|
iproute2 \
|
|
libcap2-bin \
|
|
openssh-client \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Allow binding to privileged ports (e.g. 990/FTPS) as non-root user.
|
|
# File capabilities are more reliable than Docker cap_add with user: directive,
|
|
# which depends on ambient capability support in the container runtime.
|
|
RUN setcap cap_net_bind_service=+ep "$(readlink -f /usr/local/bin/python3)"
|
|
|
|
# Install Python dependencies with cache mount
|
|
COPY requirements.txt ./
|
|
RUN --mount=type=cache,target=/root/.cache/pip \
|
|
pip install --root-user-action=ignore -r requirements.txt
|
|
|
|
# Copy backend
|
|
COPY backend/ ./backend/
|
|
|
|
# Capture the current git branch at build time. `.git/HEAD` is the only
|
|
# .git metadata the build context lets through (see .dockerignore); it
|
|
# contains `ref: refs/heads/<branch>`, which the SpoolBuddy remote-update
|
|
# flow reads at runtime via detect_current_branch() in spoolbuddy_ssh.py.
|
|
# Without this, the production image has no git metadata at all and would
|
|
# always pull `main` on the remote device regardless of which branch
|
|
# Bambuddy itself was built from.
|
|
COPY .git/HEAD ./.git/HEAD
|
|
|
|
# Copy built frontend from builder stage
|
|
COPY --from=frontend-builder /app/static ./static
|
|
|
|
# Create data directory for persistent storage
|
|
# chmod 777 allows running as non-root user (e.g., with docker compose user: directive)
|
|
RUN mkdir -p /app/data /app/logs && chmod 777 /app/data /app/logs
|
|
|
|
# Environment variables
|
|
ENV PYTHONUNBUFFERED=1
|
|
ENV DATA_DIR=/app/data
|
|
ENV LOG_DIR=/app/logs
|
|
ENV PORT=8000
|
|
# Provide a local username + home for tools that call getpass.getuser() /
|
|
# os.path.expanduser() under arbitrary PUIDs. With `user: "1001:1001"` the
|
|
# stock python:3.13-slim image has no /etc/passwd entry for that UID, so
|
|
# pwd.getpwuid() raises and breaks libraries that do host-level user lookups
|
|
# (notably asyncssh, which uses the local username for ~/.ssh/config host
|
|
# matching during the SpoolBuddy remote-update flow). Setting LOGNAME/USER
|
|
# makes getpass.getuser() resolve via env vars instead of the passwd db;
|
|
# HOME=/app gives a writable home that is guaranteed to exist.
|
|
ENV HOME=/app
|
|
ENV USER=bambuddy
|
|
ENV LOGNAME=bambuddy
|
|
|
|
EXPOSE 322
|
|
EXPOSE 990
|
|
EXPOSE 3000
|
|
EXPOSE 3002
|
|
EXPOSE 6000
|
|
EXPOSE 8000
|
|
EXPOSE 8883
|
|
EXPOSE 50000-50100
|
|
|
|
# Health check (uses PORT env var via shell)
|
|
HEALTHCHECK --interval=30s --timeout=10s --start-period=10s --retries=3 \
|
|
CMD python -c "import urllib.request, os; urllib.request.urlopen(f'http://localhost:{os.environ.get(\"PORT\", \"8000\")}/health')" || exit 1
|
|
|
|
# Run the application
|
|
# Use standard asyncio loop (uvloop has permission issues in some Docker environments)
|
|
# Port is configurable via PORT environment variable (default: 8000)
|
|
CMD ["sh", "-c", "uvicorn backend.app.main:app --host 0.0.0.0 --port ${PORT:-8000} --loop asyncio"]
|