44402f01d6
CI/CD Pipeline / Check if frontend-only change (push) Has been skipped
CI/CD Pipeline / Build Production API Image (push) Has been skipped
CI/CD Pipeline / Build Production Web Image (push) Has been skipped
CI/CD Pipeline / Build Production Worker Image (push) Has been skipped
CI/CD Pipeline / Deploy Production (push) Has been skipped
CI/CD Pipeline / Production Browser E2E (push) Has been skipped
CI/CD Pipeline / Build Staging Web Image (push) Successful in 29s
CI/CD Pipeline / Validate Code Quality And Tests (push) Successful in 2m20s
CI/CD Pipeline / Frontend Unit Tests (push) Successful in 2m31s
CI/CD Pipeline / Build Staging API Image (push) Successful in 2m42s
CI/CD Pipeline / Unit Tests (push) Successful in 2m40s
CI/CD Pipeline / Frontend Lint (push) Successful in 2m57s
CI/CD Pipeline / Integration Tests (push) Successful in 1m5s
CI/CD Pipeline / Build Staging Worker Image (push) Successful in 28m58s
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (push) Successful in 4m12s
CI/CD Pipeline / ACR Image Cleanup (push) Successful in 46s
CI/CD Pipeline / Staging E2E Tests (push) Successful in 20m19s
CI/CD Pipeline / Staging API Integration Tests (push) Successful in 22m33s
Co-authored-by: xiaoxia <dev@xiaoxiajianji.com> Co-committed-by: xiaoxia <dev@xiaoxiajianji.com>
119 lines
4.6 KiB
Docker
Executable File
119 lines
4.6 KiB
Docker
Executable File
# ============================================================
|
||
# Worker Dockerfile - 优化版(多阶段构建 + 镜像瘦身 + cache mount加速)
|
||
# 优化项:
|
||
# 1. 多阶段构建:builder 阶段安装编译依赖,runtime 阶段只保留运行时
|
||
# 2. ffmpeg 通过 apt 安装(阿里云镜像加速,几秒完成,稳定可靠)
|
||
# 3. Python 依赖瘦身:strip .so 调试符号 + 清理测试文件 + 清理缓存
|
||
# 4. pip cache mount:加速依赖下载(跨构建共享pip wheel缓存)
|
||
# ============================================================
|
||
|
||
# ==================== Builder 阶段 ====================
|
||
FROM git.xiaoxiajianji.com/xiaoxia/base/python:3.12-slim AS builder
|
||
|
||
# 使用阿里云镜像加速
|
||
RUN sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list.d/debian.sources 2>/dev/null || \
|
||
sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list 2>/dev/null || true
|
||
|
||
# 安装编译工具(仅 builder 需要)
|
||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||
gcc \
|
||
g++ \
|
||
python3-dev \
|
||
binutils \
|
||
&& rm -rf /var/lib/apt/lists/*
|
||
|
||
|
||
# ---- 安装 Python 依赖 ----
|
||
WORKDIR /tmp
|
||
|
||
# 创建 venv
|
||
RUN python -m venv /opt/venv
|
||
ENV PATH="/opt/venv/bin:$PATH"
|
||
|
||
# 基础依赖
|
||
COPY requirements-base.txt /tmp/requirements-base.txt
|
||
RUN --mount=type=cache,target=/root/.cache/pip,sharing=locked \
|
||
pip install --no-cache-dir -i https://mirrors.aliyun.com/pypi/simple/ --trusted-host mirrors.aliyun.com \
|
||
-r /tmp/requirements-base.txt \
|
||
&& rm /tmp/requirements-base.txt
|
||
|
||
# Worker 专属大包
|
||
COPY requirements-worker.txt /tmp/requirements-worker.txt
|
||
RUN --mount=type=cache,target=/root/.cache/pip,sharing=locked \
|
||
pip install --no-cache-dir -i https://mirrors.aliyun.com/pypi/simple/ --trusted-host mirrors.aliyun.com \
|
||
-r /tmp/requirements-worker.txt \
|
||
&& rm /tmp/requirements-worker.txt
|
||
|
||
# 业务依赖
|
||
COPY requirements.txt /tmp/requirements.txt
|
||
RUN --mount=type=cache,target=/root/.cache/pip,sharing=locked \
|
||
pip install --no-cache-dir -i https://mirrors.aliyun.com/pypi/simple/ --trusted-host mirrors.aliyun.com \
|
||
-r /tmp/requirements.txt \
|
||
&& rm /tmp/requirements.txt
|
||
|
||
# ---- Python 依赖瘦身 ----
|
||
# 1. strip .so 文件的调试符号(节省约 80-100MB)
|
||
RUN find /opt/venv -name "*.so" -type f -exec strip --strip-all {} \; 2>/dev/null || true
|
||
|
||
# 2. 清理测试文件(节省约 20MB)
|
||
RUN find /opt/venv -type d -name "tests" -exec rm -rf {} + 2>/dev/null; \
|
||
find /opt/venv -type d -name "test" -exec rm -rf {} + 2>/dev/null; \
|
||
find /opt/venv -name "test_*.py" -delete 2>/dev/null || true
|
||
|
||
# 3. 清理 .pyc 缓存和 __pycache__(节省约 10MB,运行时按需生成)
|
||
RUN find /opt/venv -type d -name "__pycache__" -exec rm -rf {} + 2>/dev/null; \
|
||
find /opt/venv -name "*.pyc" -delete 2>/dev/null || true
|
||
|
||
# 4. 清理 dist-info 中的文档
|
||
RUN find /opt/venv -name "*.dist-info" -type d -exec sh -c 'rm -f "$1"/DESCRIPTION.rst "$1"/INSTALLER "$1"/LICENSE* "$1"/WHEEL "$1"/entry_points.txt' _ {} \; 2>/dev/null || true
|
||
|
||
# ==================== Runtime 阶段 ====================
|
||
FROM git.xiaoxiajianji.com/xiaoxia/base/python:3.12-slim AS runtime
|
||
|
||
# 构建参数:版本号
|
||
ARG APP_VERSION=dev
|
||
|
||
# 使用阿里云镜像加速
|
||
RUN sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list.d/debian.sources 2>/dev/null || \
|
||
sed -i 's|deb.debian.org|mirrors.aliyun.com|g' /etc/apt/sources.list 2>/dev/null || true
|
||
|
||
# 安装最小运行时依赖(opencv-python-headless 需要 libglib2.0-0)
|
||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||
ffmpeg \
|
||
libglib2.0-0 \
|
||
&& rm -rf /var/lib/apt/lists/*
|
||
|
||
# 从 builder 复制 Python 虚拟环境
|
||
COPY --from=builder /opt/venv /opt/venv
|
||
|
||
# 设置工作目录
|
||
WORKDIR /app
|
||
|
||
# 复制应用代码
|
||
COPY apps/worker/ /app/apps/worker/
|
||
COPY apps/api/app/config.py /app/apps/api/app/config.py
|
||
COPY apps/api/app/core/ /app/apps/api/app/core/
|
||
COPY packages/ /app/packages/
|
||
COPY alembic.ini /app/alembic.ini
|
||
COPY migrations/ /app/migrations/
|
||
|
||
# 复制 Worker 启动脚本
|
||
COPY infra/docker/entrypoint-worker.sh /usr/local/bin/entrypoint-worker.sh
|
||
RUN chmod +x /usr/local/bin/entrypoint-worker.sh
|
||
|
||
# 设置 Python 路径
|
||
ENV PATH="/opt/venv/bin:$PATH"
|
||
ENV PYTHONPATH=/app:/app/packages
|
||
ENV PYTHONUNBUFFERED=1
|
||
ENV APP_VERSION=$APP_VERSION
|
||
|
||
# 创建非 root 用户运行 Worker
|
||
RUN groupadd -r celery && useradd -r -g celery -d /app -s /sbin/nologin celery \
|
||
&& mkdir -p /app/generated && chown celery:celery /app/generated
|
||
|
||
USER celery
|
||
|
||
# Worker 入口点
|
||
WORKDIR /app/apps/worker
|
||
CMD ["/usr/local/bin/entrypoint-worker.sh"]
|