mirror of
https://github.com/open-jarvis/OpenJarvis.git
synced 2026-07-27 21:05:34 +00:00
Pin all base images and ollama to fixed versions + @sha256 digests (no floating :latest), run Docker images as an unprivileged openjarvis user (uid 10001), replace the curl|bash NodeSource install with a digest-pinned multi-stage copy, install from the committed uv.lock via uv export --frozen --no-dev (hash-verified, --no-deps), and add systemd sandboxing (NoNewPrivileges, ProtectSystem=strict, PrivateTmp, kernel/SUID protections). Closes #228, #563, #564, #565, #566, #567.
61 lines
2.1 KiB
Docker
61 lines
2.1 KiB
Docker
# Base images are pinned to an immutable digest (in addition to a human-readable
|
|
# tag) so every build resolves the exact same layers — reproducible builds and
|
|
# safe rollbacks (#563).
|
|
|
|
# Stage 1: Build frontend SPA
|
|
FROM node:22.23.0-slim@sha256:d9f850096136edbc402debdd8729579a288aac64574ada0ff4db26b6ae58b0b2 AS frontend
|
|
|
|
WORKDIR /frontend
|
|
COPY frontend/package.json frontend/package-lock.json* ./
|
|
RUN npm ci --ignore-scripts 2>/dev/null || npm install
|
|
COPY frontend/ .
|
|
RUN npm run build
|
|
|
|
# Stage 2: Build Python package (NVIDIA CUDA 12.4)
|
|
FROM nvidia/cuda:12.4.0-runtime-ubuntu22.04@sha256:af8bd179ed3bf69d4b63b19a763662a6141f0f62ef099283f68d0b14b4bab0e3 AS builder
|
|
|
|
RUN apt-get update && \
|
|
apt-get install -y --no-install-recommends python3 python3-pip python3-venv && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
WORKDIR /app
|
|
|
|
# Install dependencies from the committed lockfile (#567). See deploy/docker/Dockerfile
|
|
# for the rationale behind the frozen export + --no-deps install.
|
|
COPY pyproject.toml uv.lock README.md ./
|
|
RUN pip install --no-cache-dir uv && \
|
|
uv export --frozen --no-dev --extra server --no-emit-project > requirements.txt && \
|
|
uv pip install --system --no-deps -r requirements.txt
|
|
|
|
COPY src/ src/
|
|
COPY scripts/install scripts/install
|
|
COPY deploy/windows deploy/windows
|
|
|
|
COPY --from=frontend /src/openjarvis/server/static src/openjarvis/server/static/
|
|
|
|
RUN uv pip install --system --no-deps .
|
|
|
|
# Stage 3: Runtime
|
|
FROM nvidia/cuda:12.4.0-runtime-ubuntu22.04@sha256:af8bd179ed3bf69d4b63b19a763662a6141f0f62ef099283f68d0b14b4bab0e3
|
|
|
|
RUN apt-get update && \
|
|
apt-get install -y --no-install-recommends python3 python3-pip && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
COPY --from=builder /usr/local /usr/local
|
|
COPY --from=builder /app /app
|
|
WORKDIR /app
|
|
|
|
# Run as an unprivileged user (#565). NVIDIA device nodes (/dev/nvidia*) are
|
|
# world-accessible, so GPU workloads do not require root.
|
|
RUN groupadd --system --gid 10001 openjarvis && \
|
|
useradd --system --uid 10001 --gid openjarvis \
|
|
--create-home --home-dir /home/openjarvis openjarvis
|
|
ENV HOME=/home/openjarvis
|
|
USER openjarvis
|
|
|
|
EXPOSE 8000
|
|
|
|
ENTRYPOINT ["jarvis"]
|
|
CMD ["serve", "--host", "0.0.0.0", "--port", "8000"]
|