* chore: update Dockerfile for monitor service to create a non-root user and adjust permissions for improved security * chore: enhance Docker entrypoints to support non-root execution and improve log directory permissions
69 lines
1.6 KiB
Docker
69 lines
1.6 KiB
Docker
FROM python:3.12.10-alpine
|
|
|
|
# set environment variables
|
|
ENV PYTHONDONTWRITEBYTECODE=1
|
|
ENV PYTHONUNBUFFERED=1
|
|
ENV PIP_DISABLE_PIP_VERSION_CHECK=1
|
|
ENV INSTANCE_CHANGELOG_URL=https://sites.plane.so/pages/f366114e9aba4cbfbe4265b8f2b74f65/
|
|
|
|
# Update system packages for security
|
|
RUN apk update && apk upgrade
|
|
|
|
WORKDIR /code
|
|
|
|
RUN apk add --no-cache --upgrade \
|
|
"libpq" \
|
|
"libxslt" \
|
|
"xmlsec" \
|
|
"ca-certificates" \
|
|
"openssl" \
|
|
"openldap-dev" \
|
|
"su-exec"
|
|
|
|
COPY requirements.txt ./
|
|
COPY requirements ./requirements
|
|
RUN apk add --no-cache libffi-dev
|
|
RUN apk add --no-cache --virtual .build-deps \
|
|
"bash~=5.2" \
|
|
"g++" \
|
|
"gcc" \
|
|
"cargo" \
|
|
"git" \
|
|
"make" \
|
|
"postgresql-dev" \
|
|
"libc-dev" \
|
|
"linux-headers" \
|
|
"xmlsec-dev"\
|
|
&& \
|
|
pip install -r requirements.txt --compile --no-cache-dir \
|
|
&& \
|
|
apk del .build-deps \
|
|
&& \
|
|
rm -rf /var/cache/apk/*
|
|
|
|
|
|
# Add in Django deps and generate Django's static files
|
|
COPY manage.py manage.py
|
|
COPY plane plane/
|
|
COPY templates templates/
|
|
COPY package.json package.json
|
|
|
|
RUN apk --no-cache add "bash~=5.2"
|
|
COPY ./bin ./bin/
|
|
|
|
COPY LICENSE.txt .
|
|
RUN mkdir -p /usr/share/licenses/plane/
|
|
COPY LICENSE.txt /usr/share/licenses/plane/LICENSE.txt
|
|
|
|
# Create user first so chown can reference it by name
|
|
RUN addgroup -g 1000 plane && adduser -u 1000 -G plane -s /bin/sh -D plane
|
|
|
|
RUN mkdir -p /code/plane/logs && \
|
|
chmod +x ./bin/* && \
|
|
chmod -R 755 /code && \
|
|
chown -R plane:plane /code
|
|
|
|
# Expose container port and run entry point script
|
|
EXPOSE 8000
|
|
|
|
CMD ["./bin/docker-entrypoint-api.sh"] |