-
-
Notifications
You must be signed in to change notification settings - Fork 41
Expand file tree
/
Copy pathDockerfile.viewer
More file actions
66 lines (54 loc) · 2.55 KB
/
Copy pathDockerfile.viewer
File metadata and controls
66 lines (54 loc) · 2.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
FROM python:3.14-slim
# Set working directory
WORKDIR /app
# Install system libraries for Pillow + ffmpeg for video thumbnail extraction
RUN apt-get update && apt-get install -y --no-install-recommends \
libjpeg62-turbo libwebp7 libwebpmux3 zlib1g \
ffmpeg \
&& rm -rf /var/lib/apt/lists/*
# Install uv for fast, reproducible dependency installation
COPY --from=ghcr.io/astral-sh/uv:0.11 /uv /bin/uv
# Install dependencies (locked versions)
# --locked fails the build if uv.lock is out of date with pyproject.toml,
# instead of silently shipping an image that is missing a declared dependency.
COPY pyproject.toml uv.lock ./
# Only the viewer's runtime group: the exposed image must not carry the
# capture stack (telethon, cryptg, psycopg2-binary, APScheduler) it can
# never import.
RUN uv sync --locked --no-install-project --only-group viewer-runtime
# Copy only the necessary application code for the viewer
COPY telegram_archive/__init__.py ./telegram_archive/
COPY telegram_archive/config.py ./telegram_archive/
COPY telegram_archive/realtime.py ./telegram_archive/
COPY telegram_archive/status.py ./telegram_archive/
COPY telegram_archive/message_utils.py ./telegram_archive/
COPY telegram_archive/transcription_contract.py ./telegram_archive/
COPY telegram_archive/db/ ./telegram_archive/db/
COPY telegram_archive/web/ ./telegram_archive/web/
# The old package name, so a compose file that runs "uvicorn src.web.main:app" keeps working.
COPY src/ ./src/
# Wallpapers used to be mounted at /app/src/web/static/<file>. Keep that path
# pointing at the static directory the viewer serves.
RUN mkdir -p /app/src/web && ln -s /app/telegram_archive/web/static /app/src/web/static
COPY scripts/healthcheck_viewer.py ./scripts/healthcheck_viewer.py
# Create non-root user for security
RUN useradd -m -u 1000 telegram && \
mkdir -p /data/backups && \
chown -R telegram:telegram /app /data
# Switch to non-root user
USER telegram
# Set default environment variables
ENV BACKUP_PATH=/data/backups \
LOG_LEVEL=INFO \
PYTHONPATH=/app \
PATH="/app/.venv/bin:$PATH"
# Volume for persistent data (read-only access to backups)
VOLUME ["/data"]
# Healthy means /api/health answers "ok" — "degraded" (database unreachable)
# is unhealthy, because a viewer that cannot read the archive is not serving.
HEALTHCHECK --interval=30s --timeout=10s --start-period=30s --retries=3 \
CMD ["python3", "/app/scripts/healthcheck_viewer.py"]
# Expose web viewer port
EXPOSE 8000
# Run web viewer
CMD ["uvicorn", "telegram_archive.web.main:app", "--host", "0.0.0.0", "--port", "8000"]