110 lines
3.4 KiB
Docker
110 lines
3.4 KiB
Docker
# SPDX-FileCopyrightText: 2023 James R. Barlow
|
|
# SPDX-License-Identifier: MPL-2.0
|
|
|
|
FROM alpine:3.24 AS base
|
|
|
|
ENV LANG=C.UTF-8
|
|
ENV TZ=UTC
|
|
|
|
RUN apk add --no-cache \
|
|
python3 \
|
|
zlib
|
|
|
|
FROM base AS builder
|
|
|
|
# Yes it really is python3-dev, and py3-package
|
|
RUN apk add --no-cache \
|
|
ca-certificates \
|
|
git \
|
|
python3-dev \
|
|
py3-pyarrow \
|
|
curl
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=ghcr.io/astral-sh/uv:0.11.21 /uv /uvx /bin/
|
|
|
|
ENV UV_COMPILE_BYTECODE=1 UV_LINK_MODE=copy
|
|
|
|
RUN uv venv --system-site-packages .venv
|
|
|
|
# Install the project's dependencies using the lockfile and settings
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
--mount=type=bind,source=uv.lock,target=uv.lock \
|
|
--mount=type=bind,source=pyproject.toml,target=pyproject.toml \
|
|
uv sync --frozen --no-install-project --no-dev
|
|
|
|
# Then, add the rest of the project source code and install it
|
|
# Installing separately from its dependencies allows optimal layer caching
|
|
COPY . /app
|
|
RUN --mount=type=cache,target=/root/.cache/uv \
|
|
uv sync --frozen \
|
|
--extra webservice --extra watcher --extra webui --no-dev \
|
|
--no-install-package pyarrow
|
|
|
|
FROM base
|
|
|
|
RUN apk add --no-cache \
|
|
ghostscript \
|
|
jbig2dec \
|
|
jbig2enc \
|
|
pngquant \
|
|
tesseract-ocr \
|
|
tesseract-ocr-data-chi_sim \
|
|
tesseract-ocr-data-deu \
|
|
tesseract-ocr-data-eng \
|
|
tesseract-ocr-data-fra \
|
|
tesseract-ocr-data-osd \
|
|
tesseract-ocr-data-por \
|
|
tesseract-ocr-data-spa \
|
|
font-noto \
|
|
ttf-droid \
|
|
unpaper \
|
|
&& rm -rf /var/cache/apk/*
|
|
|
|
# Create a non-root user to run the application (defense in depth). The build
|
|
# stages above need root to install packages, but the entrypoint should not.
|
|
# A fixed uid/gid of 1000 keeps `--user`/`--userns keep-id` mappings predictable
|
|
# and matches the --chown below. See docs/docker.md for the volume/permissions
|
|
# implications under rootless vs rootful Docker.
|
|
RUN addgroup -g 1000 app \
|
|
&& adduser -u 1000 -G app -D -h /home/app app
|
|
ENV HOME=/home/app
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=builder --chown=app:app /app /app
|
|
|
|
RUN rm -rf /app/.git && \
|
|
ln -s /app/misc/webservice.py /app/webservice.py && \
|
|
ln -s /app/misc/watcher.py /app/watcher.py && \
|
|
chown app:app /app
|
|
|
|
# Default working directory for bind-mounted data, so relative input/output
|
|
# paths work without passing --workdir (e.g. `-v "$PWD:/data" in.pdf out.pdf`).
|
|
# The webservice/watcher are run by absolute path (/app/*.py), unaffected by this.
|
|
RUN mkdir -p /data && chown app:app /data
|
|
|
|
# Scratch space for the batch web interface (webui/). Uploads and results live
|
|
# here and are deleted once their batch expires; nothing in it needs to
|
|
# survive a restart, so it is a good candidate for a tmpfs mount.
|
|
RUN mkdir -p /var/tmp/ocrmypdf-webui && chown app:app /var/tmp/ocrmypdf-webui
|
|
|
|
WORKDIR /data
|
|
|
|
ENV PATH="/app/.venv/bin:${PATH}"
|
|
# webui/ is a top-level package in the source tree rather than part of the
|
|
# installed ocrmypdf distribution, so it has to be on the import path.
|
|
ENV PYTHONPATH="/app"
|
|
|
|
# Batch web interface. Not published by the default entrypoint; start it with
|
|
# docker run -p 8000:8000 --entrypoint python3 <image> -m webui
|
|
EXPOSE 8000
|
|
|
|
# Drop privileges: run the entrypoint (ocrmypdf, or the webservice/watcher when
|
|
# overridden) as the unprivileged app user. Override with `--user root` if you
|
|
# need root inside a running container (e.g. to apk add extra packages).
|
|
USER app
|
|
|
|
ENTRYPOINT ["/app/.venv/bin/ocrmypdf"]
|