# ============================================================ # Worker Dockerfile - 优化版(多阶段构建 + 镜像瘦身 + cache mount加速) # 优化项: # 1. 多阶段构建:builder 阶段安装编译依赖,runtime 阶段只保留运行时 # 2. ffmpeg 通过 apt 安装(阿里云镜像加速,几秒完成,稳定可靠) # 3. Python 依赖瘦身:strip .so 调试符号 + 清理测试文件 + 清理缓存 # 4. pip cache mount:加速依赖下载(跨构建共享pip wheel缓存) # ============================================================ # ==================== Builder 阶段 ==================== FROM git.xiaoxiajianji.com/xiaoxia/base/python:3.12-slim AS builder # 使用阿里云镜像加速 RUN sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list.d/debian.sources 2>/dev/null || \ sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list 2>/dev/null || true # 安装编译工具(仅 builder 需要) RUN apt-get update && apt-get install -y --no-install-recommends \ gcc \ g++ \ python3-dev \ binutils \ && rm -rf /var/lib/apt/lists/* # ---- 安装 Python 依赖 ---- WORKDIR /tmp # 创建 venv RUN python -m venv /opt/venv ENV PATH="/opt/venv/bin:$PATH" # 基础依赖 COPY requirements-base.txt /tmp/requirements-base.txt RUN --mount=type=cache,target=/root/.cache/pip,sharing=locked \ pip install --no-cache-dir -i https://mirrors.aliyun.com/pypi/simple/ --trusted-host mirrors.aliyun.com \ -r /tmp/requirements-base.txt \ && rm /tmp/requirements-base.txt # Worker 专属大包 COPY requirements-worker.txt /tmp/requirements-worker.txt RUN --mount=type=cache,target=/root/.cache/pip,sharing=locked \ pip install --no-cache-dir -i https://mirrors.aliyun.com/pypi/simple/ --trusted-host mirrors.aliyun.com \ -r /tmp/requirements-worker.txt \ && rm /tmp/requirements-worker.txt # 业务依赖 COPY requirements.txt /tmp/requirements.txt RUN --mount=type=cache,target=/root/.cache/pip,sharing=locked \ pip install --no-cache-dir -i https://mirrors.aliyun.com/pypi/simple/ --trusted-host mirrors.aliyun.com \ -r /tmp/requirements.txt \ && rm /tmp/requirements.txt # ---- Python 依赖瘦身 ---- # 1. strip .so 文件的调试符号(节省约 80-100MB) RUN find /opt/venv -name "*.so" -type f -exec strip --strip-all {} \; 2>/dev/null || true # 2. 清理测试文件(节省约 20MB) RUN find /opt/venv -type d -name "tests" -exec rm -rf {} + 2>/dev/null; \ find /opt/venv -type d -name "test" -exec rm -rf {} + 2>/dev/null; \ find /opt/venv -name "test_*.py" -delete 2>/dev/null || true # 3. 清理 .pyc 缓存和 __pycache__(节省约 10MB,运行时按需生成) RUN find /opt/venv -type d -name "__pycache__" -exec rm -rf {} + 2>/dev/null; \ find /opt/venv -name "*.pyc" -delete 2>/dev/null || true # 4. 清理 dist-info 中的文档 RUN find /opt/venv -name "*.dist-info" -type d -exec sh -c 'rm -f "$1"/DESCRIPTION.rst "$1"/INSTALLER "$1"/LICENSE* "$1"/WHEEL "$1"/entry_points.txt' _ {} \; 2>/dev/null || true # ==================== Runtime 阶段 ==================== FROM git.xiaoxiajianji.com/xiaoxia/base/python:3.12-slim AS runtime # 构建参数:版本号 ARG APP_VERSION=dev # 使用阿里云镜像加速 RUN sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list.d/debian.sources 2>/dev/null || \ sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list 2>/dev/null || true # 安装最小运行时依赖(opencv-python-headless 需要 libglib2.0-0) RUN apt-get update && apt-get install -y --no-install-recommends \ ffmpeg \ libglib2.0-0 \ && rm -rf /var/lib/apt/lists/* # 从 builder 复制 Python 虚拟环境 COPY --from=builder /opt/venv /opt/venv # 设置工作目录 WORKDIR /app # 复制应用代码 COPY apps/worker/ /app/apps/worker/ COPY apps/api/app/config.py /app/apps/api/app/config.py COPY apps/api/app/core/ /app/apps/api/app/core/ COPY packages/ /app/packages/ COPY alembic.ini /app/alembic.ini COPY migrations/ /app/migrations/ # 复制 Worker 启动脚本 COPY infra/docker/entrypoint-worker.sh /usr/local/bin/entrypoint-worker.sh RUN chmod +x /usr/local/bin/entrypoint-worker.sh # 设置 Python 路径 ENV PATH="/opt/venv/bin:$PATH" ENV PYTHONPATH=/app:/app/packages ENV PYTHONUNBUFFERED=1 ENV APP_VERSION=$APP_VERSION # 创建非 root 用户运行 Worker RUN groupadd -r celery && useradd -r -g celery -d /app -s /sbin/nologin celery \ && mkdir -p /app/generated && chown celery:celery /app/generated USER celery # Worker 入口点 WORKDIR /app/apps/worker CMD ["/usr/local/bin/entrypoint-worker.sh"]