FROM python:3.11-slim WORKDIR /app COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt COPY netplan_v4 ./netplan_v4 COPY tests ./tests COPY run_tests.py install_hooks.py runtime_preflight.py Dockerfile . COPY integrations ./integrations COPY gui ./gui COPY release_preflight.py forecast_acceptance.py deploy_integrated_shadow.py approved_previous_assets.json ./ COPY acceptance ./acceptance COPY commissioning/deploy_application.py ./commissioning/deploy_application.py # Host sources can be 0600/0700. COPY makes them root-owned. # Normalize only packaged application code; never change host secrets or sockets. RUN find /app -type d -exec chmod 0755 {} + \ && find /app -type f -exec chmod 0644 {} + ENV PYTHONDONTWRITEBYTECODE=1 \ PYTHONUNBUFFERED=1 \ NETPLAN_V4_TEST_REPORT_DIR=/tmp/test-results USER 1000:1000 # Fail the build early if the actual unprivileged runtime cannot read the code. RUN python /app/runtime_preflight.py CMD ["uvicorn", "netplan_v4.service:from_environment", "--factory", "--host", "0.0.0.0", "--port", "9100", "--workers", "1"]