23 lines
553 B
Text
23 lines
553 B
Text
|
|
FROM python:3.12-slim
|
||
|
|
|
||
|
|
# Prevent Python from writing .pyc files and buffer stdout/stderr for clean logging
|
||
|
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
||
|
|
PYTHONUNBUFFERED=1
|
||
|
|
|
||
|
|
WORKDIR /app
|
||
|
|
|
||
|
|
# Install dependencies first to leverage Docker layer caching
|
||
|
|
COPY requirements.txt .
|
||
|
|
RUN pip install --no-cache-dir -r requirements.txt
|
||
|
|
|
||
|
|
# Copy application source code
|
||
|
|
COPY matrix_keycloak_bot.py .
|
||
|
|
|
||
|
|
# Security best practice: run as a non-root user
|
||
|
|
RUN useradd -m -u 10001 botuser && \
|
||
|
|
chown -R botuser:botuser /app
|
||
|
|
|
||
|
|
USER botuser
|
||
|
|
|
||
|
|
CMD ["python", "matrix_keycloak_bot.py"]
|