# Use an official Python runtime as a parent image FROM python:3.9-slim-bookworm # --- Basic runtime hygiene --- ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 # Workdir WORKDIR /usr/src/app # Install OS deps first (so pip layer can cache better) # You mentioned custom markovify & git, so we keep git. RUN apt-get update && apt-get install -y --no-install-recommends \ git \ && rm -rf /var/lib/apt/lists/* # Copy only requirements first to leverage Docker layer cache COPY requirements.txt . # Install Python deps RUN pip install --no-cache-dir -r requirements.txt # Copy the rest of your app COPY . . # Create a non-root user and give ownership RUN adduser --disabled-password --gecos "" appuser \ && chown -R appuser:appuser /usr/src/app USER appuser # Default cache dir (override with TEXTS_CACHE_DIR env if you want) ENV DB_DIR=/usr/src/app/db RUN mkdir -p "$DB_DIR" # Expose the service port EXPOSE 5000 CMD ["python", "-u", "db.py"]