Harden the Docker images by dropping root privileges, and make the
bind-mount workflow less fiddly.
- Create a non-root `app` user (uid/gid 1000) in both images and add
`USER app` before the entrypoint, so ocrmypdf (and the
webservice/watcher) no longer run as root. This also fixes the
previously dangling `--chown=app:app`, which referenced a user that
was never created. The Ubuntu base ships a default `ubuntu`/1000 user,
so remove it first so `app` can take uid 1000 (parity with Alpine).
- Add `WORKDIR /data` (created and app-owned) so bind-mounted input and
output can be passed as relative paths without `--workdir`. The
webservice/watcher are now invoked by absolute path (`/app/*.py`)
since the working directory is no longer `/app`.
- Drop the redundant `ppa:alex-p/tesseract-ocr5` from the Ubuntu image:
Tesseract 5 ships in the Ubuntu archive as of 24.04, and the PPA had
no build for the 26.04 base, which broke the build outright.
- Rewrite docs/docker.md rootless-first: stdin/stdout piping as the
recommended permission-free path, then per-runtime volume guidance
(rootless Docker `--user 0:0`, Podman `--userns keep-id`, rootful
Docker as the special case). Update batch.md and the compose example
to match (absolute script paths, per-runtime `user:` guidance).
Establish clear separation between user-facing optional dependencies
and developer-only dependency groups:
**Optional Dependencies (user features):**
- watcher: File watching service for batch processing
- webservice: Streamlit-based web UI
- Installable via: uv sync --extra <name> or pip install ocrmypdf[name]
**Dependency Groups (developer tools):**
- test: Testing infrastructure (merged from test + extended_test)
- docs: Documentation building tools
- streamlit-dev: Enhanced Streamlit development tools
- dev: General development tools (mypy, ipykernel)
- Installable via: uv sync --group <name> (uv only, NOT pip)
Breaking changes for developers:
- pip install -e .[test] no longer works → use uv sync --group test
- pip install -e .[docs] no longer works → use uv sync --group docs
- pip install -e .[extended_test] removed → merged into test group
No breaking changes for end users:
- pip install ocrmypdf[watcher] still works
- pip install ocrmypdf[webservice] still works
Updated:
- CI/CD workflows to use uv sync --group test
- Docker images to exclude test dependencies
- Documentation to recommend uv with pip as fallback
- pyproject.toml with clear comments explaining both systems
tesseract-ocr/alex-p does not have a Tesseract 5 for Ubuntu 25.10 so we use 25.04 for now.
Ubuntu 25.04 gets us Ghostscript 10.05 which avoids issues in older versions.
Remove comment about now-legacy Alpine versions not working properly. Alpine provides Ghostscript 10.05.1.
Fixes#1587,