fix(channels): complete dependency manifest migration (#4995)
* fix(channels): complete dependency manifest migration * docs(docker): clarify custom uid dependency installs * fix(channels): keep dependency preinstall internal * refactor(channels): move dependency installer to scripts * fix(docker): limit runtime write access
This commit is contained in:
+25
-5
@@ -15,18 +15,38 @@ RUN apt-get update && \
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
# Keep the runtime environment writable by the non-root nanobot user. Enabled
|
||||
# channels may install their manifest-declared dependencies at startup.
|
||||
ENV VIRTUAL_ENV=/app/.venv
|
||||
ENV PATH="/app/.venv/bin:$PATH"
|
||||
RUN uv venv --seed "$VIRTUAL_ENV"
|
||||
|
||||
# Install Python dependencies first (cached layer). Hatch reads the custom build
|
||||
# hook from hatch_build.py even for this metadata-only install.
|
||||
ARG NANOBOT_EXTRAS=whatsapp
|
||||
ARG NANOBOT_EXTRAS=
|
||||
COPY pyproject.toml README.md LICENSE THIRD_PARTY_NOTICES.md hatch_build.py ./
|
||||
RUN mkdir -p nanobot && touch nanobot/__init__.py && \
|
||||
NANOBOT_SKIP_WEBUI_BUILD=1 uv pip install --system --no-cache ".[$NANOBOT_EXTRAS]" && \
|
||||
if [ -n "$NANOBOT_EXTRAS" ]; then \
|
||||
NANOBOT_SKIP_WEBUI_BUILD=1 uv pip install \
|
||||
--python "$VIRTUAL_ENV/bin/python" --no-cache ".[${NANOBOT_EXTRAS}]"; \
|
||||
else \
|
||||
NANOBOT_SKIP_WEBUI_BUILD=1 uv pip install \
|
||||
--python "$VIRTUAL_ENV/bin/python" --no-cache .; \
|
||||
fi && \
|
||||
rm -rf nanobot
|
||||
|
||||
# Copy the full source and install
|
||||
COPY nanobot/ nanobot/
|
||||
COPY scripts/install_channel_dependencies.py scripts/
|
||||
COPY --from=webui-builder /app/nanobot/web/dist/ nanobot/web/dist/
|
||||
RUN NANOBOT_SKIP_WEBUI_BUILD=1 uv pip install --system --no-cache ".[$NANOBOT_EXTRAS]"
|
||||
RUN NANOBOT_SKIP_WEBUI_BUILD=1 uv pip install --python "$VIRTUAL_ENV/bin/python" --no-cache .
|
||||
|
||||
# Preinstall selected channel dependencies from their manifests. A comma-separated
|
||||
# list keeps the image configurable while preserving WhatsApp in the default image.
|
||||
ARG NANOBOT_CHANNELS=whatsapp
|
||||
RUN for channel in $(printf '%s' "$NANOBOT_CHANNELS" | tr ',' ' '); do \
|
||||
python -m scripts.install_channel_dependencies "$channel"; \
|
||||
done
|
||||
|
||||
# Render deploy template (see render.yaml): committed gateway config that wires
|
||||
# secrets through ${ANTHROPIC_API_KEY} / ${NANOBOT_WEB_TOKEN} env vars (resolved
|
||||
@@ -34,10 +54,10 @@ RUN NANOBOT_SKIP_WEBUI_BUILD=1 uv pip install --system --no-cache ".[$NANOBOT_EX
|
||||
# won't shadow it. Only used when RENDER=true; ignored by local runs.
|
||||
COPY render-config.json ./
|
||||
|
||||
# Create non-root user and config directory
|
||||
# Create the non-root user and hand ownership of the writable virtualenv to it.
|
||||
RUN useradd -m -u 1000 -s /bin/bash nanobot && \
|
||||
mkdir -p /home/nanobot/.nanobot && \
|
||||
chown -R nanobot:nanobot /home/nanobot /app
|
||||
chown -R nanobot:nanobot /home/nanobot /app/.venv
|
||||
|
||||
COPY entrypoint.sh /usr/local/bin/entrypoint.sh
|
||||
RUN sed -i 's/\r$//' /usr/local/bin/entrypoint.sh && chmod +x /usr/local/bin/entrypoint.sh
|
||||
|
||||
Reference in New Issue
Block a user