Files
butubb 74a592024c
Deploy VitePress site to Pages / build (push) Canceled after 0s
Deploy VitePress site to Pages / Deploy (push) Canceled after 0s
feat: 部署改为 git 驱动,容器以宿主用户运行
服务器实测可经 Cloudflare 443 访问 Gitea 且 git 协议正常(此前我只测了 13000 端口就断言不可达,是错的),因此不再需要 tar + SFTP。

- docker-compose: 增加 user: "1000:1000"。容器此前以 root 运行,写进挂载目录的每轮 jsonl 产物都是 root 属主,导致宿主用户连自己的部署目录都挪不动 —— 这在把部署迁到 /mnt/data 时实际发生了
- deploy.sh: 一条命令走完 拉代码 →(webui/ 有改动时)重建前端 → 重启容器。前端产物 api/webui 是 gitignore 的,git pull 带不过来,必须在服务器上重建一次
- Dockerfile: 补 npm 包。corepack 只管 yarn/pnpm 不管 npm,而前端要在服务器上重建;这样服务器只需要 Docker,不必另配 Node 环境
2026-10-07 11:13:43 +08:00

68 lines
3.2 KiB
Docker

# Server deployment image.
#
# No browser is bundled on purpose. On this deployment the crawler attaches over
# CDP to the Chrome already running on the host (see the 接管已有 Chrome setting),
# so shipping a second copy of Chromium would only add hundreds of megabytes and
# a login state that nothing uses. The Playwright Python package is still needed
# -- that is what speaks CDP -- hence PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD.
FROM python:3.11-slim
ENV PYTHONUNBUFFERED=1 \
PYTHONDONTWRITEBYTECODE=1 \
PIP_DISABLE_PIP_VERSION_CHECK=1 \
PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD=1 \
TZ=Asia/Shanghai
# asyncmy compiles a Cython extension, so a toolchain has to exist at build time.
# It is left installed: purging it risks taking libmysqlclient with it, and a
# slightly larger image is cheaper than a runtime that fails months later.
#
# deb.debian.org is effectively unusable from this network -- it was pulling the
# 96 MB of build dependencies at roughly 13 kB/s, which puts a build at well over
# half an hour. Point apt at a domestic mirror; override APT_MIRROR when building
# from somewhere that does not need it.
#
# The libgl1/libxcb1/... group is not for a GUI: opencv-python links against X11
# at import time, and tools/utils.py reaches cv2 through slider_util, so without
# them the *application* fails to import, not just some image utility. tzdata is
# here because TZ=Asia/Shanghai is silently ignored without it, which would put
# every stored timestamp in UTC. nodejs is for PyExecJS: douyin/help.py compiles
# libs/douyin.js at *import* time, and because main.py imports every platform,
# that single platform being importable-or-not decides whether the whole app
# (and the environment self-check) comes up. npm rides along so the WebUI can be
# rebuilt on the server (see deploy.sh) instead of only on a workstation --
# corepack is present but does not cover npm, only yarn and pnpm.
#
# The pip mirror is set for the same reason as the apt one: this host's route to
# the public index is slow.
ARG APT_MIRROR=mirrors.tuna.tsinghua.edu.cn
RUN set -eux; \
for f in /etc/apt/sources.list /etc/apt/sources.list.d/debian.sources; do \
if [ -f "$f" ]; then \
sed -i "s|deb.debian.org|${APT_MIRROR}|g; s|security.debian.org|${APT_MIRROR}|g" "$f"; \
fi; \
done; \
apt-get update; \
apt-get install -y --no-install-recommends \
build-essential pkg-config default-libmysqlclient-dev \
libgl1 libglib2.0-0 libsm6 libxext6 libxrender1 libxcb1 libgomp1 \
tzdata nodejs npm; \
rm -rf /var/lib/apt/lists/*
WORKDIR /app
# Requirements only -- this is the one layer that is expensive to build and
# changes rarely.
ARG PIP_INDEX=https://pypi.tuna.tsinghua.edu.cn/simple
COPY requirements.txt ./
RUN pip install --no-cache-dir -i "$PIP_INDEX" -r requirements.txt
# The application code is deliberately NOT copied in. compose mounts it at /app,
# so a code change is "re-upload the tarball, restart the container" instead of
# an image rebuild. Treat this image as the dependency layer and nothing else;
# rebuild it when, and only when, requirements.txt or this file changes.
EXPOSE 18051
# api.main reads MC_HOST / MC_PORT from the environment; compose supplies both.
CMD ["python", "-m", "api.main"]