Single consolidated commit for four completed, validated phases (77, 78, 79, 80). The pipeline run left all work uncommitted because the harness commits only with PHASE_COMMIT=1 while child executors are forbidden from committing; the phases themselves all passed validation and moved to .agents/phases/complete/. Phase 77 — navbar view refresh - router.js dispatches bor:view-refresh on re-show / active re-click / popstate (gated on wasMounted; first show and boot exempt) - History / RAG / Sources / Tuning re-fetch on refresh (admin branch); Chat deliberately excluded (stream survival) - History "Refresh" button (admin-only, in-flight disable + status line) - New story suite tests/e2e/test_navbar_refresh.py (7 tests) Phase 78 — static background - Removed the animated glow layers; static 44px grid over the flat --bg canvas; default and reduced-motion renders byte-identical - Updated background/theme E2E suites; removed bg-glow test pins Phase 79 — API tokens - api_tokens model + migration 0012; hash-only token service - Admin tokens API + Tokens admin view; POST /api/token-auth; live-revoking require_user on chat / suggestions / document content - Frontend token gate with localStorage cache; anonymous E2E suites migrated to token login - New story suite tests/e2e/test_api_tokens.py (9 tests) Phase 80 — history suggestion chips - last_questions() endpoint with SEED fallback; startNewChat() refetch - Seed-semantics docs (config.py, .env.example, README) - Integration state matrix + E2E suite rewritten to the 4 chip states Also included: phase-76 report artifacts and the repo restore-test-db skill (previously untracked), scripts/* ruff fixes from phase 77. Final gate state (phase 80 final pass, covers everything above): - uv run pytest --cov=app → 1637 passed, 0 failed, app/ coverage 99% - uv run ruff check . && uv run pyright → clean, 0 errors - Per-phase story E2E suites green in isolation
66 lines
3.3 KiB
Docker
66 lines
3.3 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Brain of Reese — production image (Podman/Docker compatible).
|
|
#
|
|
# Stage 1 (frontend): minify/bundle the local frontend with esbuild.
|
|
# NO CDN — every asset is built into this image.
|
|
# Stage 2 (python): install dependencies with uv (locked).
|
|
# Stage 3 (runtime): slim, non-root, migrations + uvicorn.
|
|
|
|
# ---------- Stage 1: frontend ----------
|
|
FROM docker.io/node:22-alpine AS frontend
|
|
WORKDIR /build
|
|
# Global install: puts the pinned esbuild binary on the PATH for the build step below
|
|
# (a local `npm install` leaves it in node_modules/.bin, invisible to RUN).
|
|
RUN npm install --no-audit --no-fund -g esbuild@0.25.5
|
|
COPY frontend ./
|
|
RUN mkdir -p /out/assets \
|
|
&& esbuild ./assets/app.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/app.js \
|
|
&& esbuild ./assets/router.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/router.js \
|
|
&& esbuild ./assets/token-gate.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/token-gate.js \
|
|
&& esbuild ./assets/document.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/document.js \
|
|
&& esbuild ./assets/login.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/login.js \
|
|
&& esbuild ./assets/shared.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/shared.js \
|
|
&& esbuild ./assets/doc-edit.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/doc-edit.js \
|
|
&& esbuild ./assets/brand.js --minify --outfile=/out/assets/brand.js \
|
|
&& esbuild ./assets/markdown.js --minify --outfile=/out/assets/markdown.js \
|
|
&& esbuild ./assets/styles.css --minify --outfile=/out/assets/styles.css \
|
|
&& cp -r ./assets/themes /out/assets/themes \
|
|
&& cp ./index.html ./document.html ./login.html ./shared.html ./doc-edit.html /out/
|
|
|
|
# ---------- Stage 2: python dependencies ----------
|
|
FROM docker.io/python:3.12-slim AS python
|
|
WORKDIR /app
|
|
COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv
|
|
COPY pyproject.toml uv.lock ./
|
|
RUN uv sync --frozen --no-dev --no-cache --no-install-project
|
|
COPY app ./app
|
|
RUN uv sync --frozen --no-dev --no-cache
|
|
|
|
# ---------- Stage 3: runtime ----------
|
|
FROM docker.io/python:3.12-slim AS runtime
|
|
ENV PATH="/app/.venv/bin:$PATH" \
|
|
PYTHONUNBUFFERED=1 \
|
|
PYTHONDONTWRITEBYTECODE=1 \
|
|
BOR_STATIC_DIR=/app/static \
|
|
BOR_ENVIRONMENT=production
|
|
RUN apt update && apt install -y git
|
|
RUN useradd --create-home --uid 10001 reese
|
|
WORKDIR /app
|
|
COPY --from=python /app/.venv /app/.venv
|
|
COPY --from=python /app/app /app/app
|
|
# app/api/sync.py (phase 32) imports scripts.git_sync / scripts.import_docs
|
|
# at module level — the scripts package must ship in the image or the
|
|
# container crashes on boot (phase 33: ModuleNotFoundError: No module
|
|
# named 'scripts').
|
|
COPY scripts ./scripts
|
|
COPY --from=frontend /out /app/static
|
|
COPY alembic ./alembic
|
|
COPY alembic.ini ./alembic.ini
|
|
COPY scripts/entrypoint.sh /usr/local/bin/entrypoint.sh
|
|
RUN chmod +x /usr/local/bin/entrypoint.sh && chown -R reese:reese /app
|
|
USER reese
|
|
EXPOSE 8000
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=5 \
|
|
CMD ["python", "-c", "import sys, httpx; sys.exit(0 if httpx.get('http://127.0.0.1:8000/api/health', timeout=4).status_code == 200 else 1)"]
|
|
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
|