- nginx: resolve real client IP through Cloudflare -> NPM so rate limits are per client instead of shared across all users - Bump vulnerable Python deps (PyJWT auth bypass, anyio, starlette via fastapi 0.141.1, cryptography, python-multipart, Mako); pin PyMySQL 1.1.2 since 1.2.x breaks SQLAlchemy 2.0.35's aiomysql ping - Backend: python 3.12.14-slim, apt-get upgrade, drop unneeded build deps - Frontend: nginx 1.30.5-alpine (stable) + apk upgrade - MySQL 8.0.40 (EOL) -> 8.4.11 LTS; add healthcheck start_period so slow startups (e.g. data upgrades) don't abort dependent services - Add maintenance review report Co-Authored-By: Claude Opus 5.5 <[email protected]>
21 lines
397 B
Docker
21 lines
397 B
Docker
FROM python:3.12.14-slim
|
|
|
|
WORKDIR /app
|
|
|
|
RUN apt-get update && apt-get upgrade -y \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
COPY requirements.txt .
|
|
RUN pip install --no-cache-dir -r requirements.txt
|
|
|
|
COPY . .
|
|
|
|
RUN adduser --disabled-password --gecos '' --uid 1000 appuser \
|
|
&& chown -R appuser /app
|
|
|
|
USER appuser
|
|
|
|
EXPOSE 8000
|
|
|
|
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
|