8155ff456b
Containerize the two non-desktop apps for the booth appliance. The desktop app stays on its own tag-only release.yml. - apps/server/Dockerfile: multi-stage node:22-alpine. `pnpm deploy --legacy --prod` (NOT prune — the monorepo native better-sqlite3 won't resolve under a root prune) yields a self-contained bundle; build stage adds node-gyp toolchain, runtime adds libstdc++; non-root, healthcheck. Migrates the mounted DB on boot via a drizzle-kit- free runtime migrator (packages/db/scripts/migrate-runtime.mjs) — drizzle-kit is a devDep, pruned from prod. - apps/server/src/static-spa.ts: Fastify serves the built React SPA (one container serves API + UI). GET-only fallback to index.html, excludes /api + /health so it never shadows the backend; a no-op in dev (no dist). Registered last in server.ts. - apps/vision/Dockerfile: uv base, --extra alpr, model weights PRE-WARMED into the image as the runtime user so fast_alpr boots offline (0 downloads at runtime). Engine env- selected (VISION_RECOGNIZER stub|fast_alpr). - Branch-aware: docker-compose.yml (base) + .dev.yml (build local, stub, ports) + .prod.yml (pull pinned, fast_alpr, vision internal, restart always); REGISTRY/TAG from env so a branch deploy pulls that branch's image. - .gitea/workflows/build-images.yml: on push to dev/main, run the full turbo build+lint+ test gate, then buildx push both images to git.infra.msai.al/mca/parking_solution with branch + branch-<sha> tags (registry cache; optional Komodo webhook behind KOMODO_ENABLED). - .dockerignore excludes **/parking.sqlite* so the signed ledger is NEVER baked. Verified locally (Docker 29): server image migrates + serves API+SPA (/health 200, / + /booth HTML, /api/nope JSON 404, no sqlite outside /data); vision image boots fast_alpr with 0 runtime downloads; compose stack healthy with server→vision over the private network. Wiki: new container-deployment.md; vision-service-packaging open Qs resolved; index + log. Claude-Session: https://claude.ai/code/session_01Xcm6ikLgGoCxxHrxtjkk5V
58 lines
2.9 KiB
Docker
58 lines
2.9 KiB
Docker
# syntax=docker/dockerfile:1.7
|
|
# Parking VISION image: the Python/uv ANPR microservice. Build CONTEXT is apps/vision
|
|
# (self-contained Python package; no monorepo deps). Ships WITH the `alpr` extra (real
|
|
# fast-alpr/onnxruntime stack) but the engine is env-selected: VISION_RECOGNIZER=stub
|
|
# (default, boots anywhere) or fast_alpr (prod). See wiki/decisions/container-deployment.md,
|
|
# wiki/decisions/vision-service-packaging.md.
|
|
|
|
# uv-provided Python 3.12 (matches apps/vision/.python-version).
|
|
FROM ghcr.io/astral-sh/uv:python3.12-bookworm-slim AS base
|
|
WORKDIR /app
|
|
ENV UV_LINK_MODE=copy \
|
|
UV_COMPILE_BYTECODE=1 \
|
|
PYTHONUNBUFFERED=1
|
|
|
|
# System libs the recognizer stack needs (opencv/onnxruntime): GL + glib. Kept minimal.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends libgl1 libglib2.0-0 \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# ---- deps: resolve + install the venv from the lockfile (cache-friendly) ----
|
|
# Manifests first so the heavy `uv sync` layer caches across source edits.
|
|
COPY pyproject.toml uv.lock .python-version ./
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --frozen --no-install-project --extra alpr
|
|
|
|
# ---- project source ----
|
|
COPY vision_service/ ./vision_service/
|
|
COPY README.md ./
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --frozen --extra alpr
|
|
|
|
# Non-root runtime user, created BEFORE the model pre-warm so the weights cache lands in
|
|
# this user's HOME (~/.cache) — the SAME path the runtime reads. (fast-alpr's
|
|
# open-image-models caches under $HOME/.cache/open-image-models keyed to HOME, ignoring
|
|
# HF_HOME/XDG_CACHE_HOME — so the pre-warm MUST run as the runtime user, not root.)
|
|
RUN useradd --system --create-home --uid 999 vision \
|
|
&& chown -R vision:vision /app
|
|
USER vision
|
|
|
|
# Pre-warm the fast-alpr model weights INTO the image (as the vision user → /home/vision/
|
|
# .cache) so the prod recognizer is OFFLINE-first: ALPR() downloads weights on first
|
|
# construction, which would otherwise need network on the appliance's first scan. Best-effort
|
|
# — if the build host has no network this is skipped and weights fetch lazily at runtime.
|
|
# NB: NO --mount=type=cache here — a BuildKit cache mount at ~/.cache is NOT committed to the
|
|
# image layer, so the downloaded weights would vanish. They must write to the real layer.
|
|
RUN uv run python -c "from fast_alpr import ALPR; ALPR()" \
|
|
|| echo "[build] model pre-warm skipped (no network) — weights fetch at runtime"
|
|
|
|
# Default to the stub recognizer (offline, no model load); override to fast_alpr in prod.
|
|
ENV VISION_RECOGNIZER=stub \
|
|
VISION_HOST=0.0.0.0 \
|
|
VISION_PORT=8089
|
|
EXPOSE 8089
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
|
|
CMD python -c "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://localhost:8089/health').status==200 else 1)" || exit 1
|
|
|
|
CMD ["uv", "run", "uvicorn", "vision_service.app:app", "--host", "0.0.0.0", "--port", "8089"]
|