Build and Push Containers / build-and-push (push) Successful in 1m50s
One env var (BOR_APP_NAME, default "Brain of Reese") now drives the app's
display name everywhere (TODO.md L12 — owner ask: "a way to customize the
name for 'Brain of'. Should be an env var."). The existing app_name setting
is the source of truth (phase locked decision — no new variable, no rename);
with the variable unset the app is byte-identical to before.
Endpoint (A10 public/stateless, no secrets):
GET /api/config → exactly {app_name, version} (app/api/config.py, the
health.py pattern; registered before the static mount). Integration tests:
anonymous 200, default values, a Settings override follows, key set is
exactly two keys — no other setting may leak in later.
Frontend brand layer (A11 — runtime fetch, static templates stay static):
assets/brand.js — a CLASSIC script, first on all six pages, so its top
level runs at parse time: window.BOR_BRAND = "Brain of Reese"
synchronously (the default renders immediately, no blank flash), then a
no-store fetch of /api/config applies the name — document.title (global
replace), every .brand-text (a name starting "Brain of " keeps the bold
split Brain of <strong>rest</strong>, any other name renders plain; the
operator-controlled name is HTML-escaped before innerHTML), a TreeWalker
over text nodes (script/style rejected — page source never rewritten),
and the aria-label/placeholder/meta-content attributes. Fetch failure
keeps the default + console.warn (the loadHealth house style).
app.js (status labels, typing label, elapsed-hint aria, tool labels) and
document.js (viewer titles) read window.BOR_BRAND at CALL time via
brand() — a label set after the fetch lands carries the configured name.
Containerfile: esbuild minify line for brand.js (classic, like markdown.js);
the phase-33 ?v= cache-busting picks the new asset ref up automatically.
E2E (A16 — one story, one file, isolated): test_configurable_brand.py boots
a SECOND app instance (same DB/mock-LLM/admin-auth env block, port APP_PORT+1,
BOR_APP_NAME="Brain of Testy") — the shared conftest server keeps the
default name so every other suite's title/label assertions stay untouched —
and asserts /api/config on both instances, the index title/brand/greeting/
#messages aria-label, the sources + login page titles, and one pre-token
chat turn (think out loud marker) whose #send-status reads "Brain of Testy
is thinking"; the no-op regression pins the shared server's default bytes.
Docs: .env.example App section + README configuration reference — what it
affects (titles, header brand, status labels, aria text), the default, the
bold-split rendering rule.
Gates: 695 unit+integration passed, app/ coverage 99% (>90%), story E2E
green in isolation (two consecutive runs), brand-string suites (smoke,
shared header, header consistency, chat persistence) green, ruff + pyright
clean.
63 lines
3.2 KiB
Docker
63 lines
3.2 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Brain of Reese — production image (Podman/Docker compatible).
|
|
#
|
|
# Stage 1 (frontend): minify/bundle the local frontend with esbuild.
|
|
# NO CDN — every asset is built into this image.
|
|
# Stage 2 (python): install dependencies with uv (locked).
|
|
# Stage 3 (runtime): slim, non-root, migrations + uvicorn.
|
|
|
|
# ---------- Stage 1: frontend ----------
|
|
FROM docker.io/node:22-alpine AS frontend
|
|
WORKDIR /build
|
|
# Global install: puts the pinned esbuild binary on the PATH for the build step below
|
|
# (a local `npm install` leaves it in node_modules/.bin, invisible to RUN).
|
|
RUN npm install --no-audit --no-fund -g esbuild@0.25.5
|
|
COPY frontend ./
|
|
RUN mkdir -p /out/assets \
|
|
&& esbuild ./assets/app.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/app.js \
|
|
&& esbuild ./assets/sources.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/sources.js \
|
|
&& esbuild ./assets/document.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/document.js \
|
|
&& esbuild ./assets/login.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/login.js \
|
|
&& esbuild ./assets/tuning.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/tuning.js \
|
|
&& esbuild ./assets/git-sources.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/git-sources.js \
|
|
&& esbuild ./assets/brand.js --minify --outfile=/out/assets/brand.js \
|
|
&& esbuild ./assets/markdown.js --minify --outfile=/out/assets/markdown.js \
|
|
&& esbuild ./assets/styles.css --minify --outfile=/out/assets/styles.css \
|
|
&& cp ./index.html ./sources.html ./document.html ./login.html ./tuning.html ./git-sources.html /out/
|
|
|
|
# ---------- Stage 2: python dependencies ----------
|
|
FROM docker.io/python:3.12-slim AS python
|
|
WORKDIR /app
|
|
COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv
|
|
COPY pyproject.toml uv.lock ./
|
|
RUN uv sync --frozen --no-dev --no-cache --no-install-project
|
|
COPY app ./app
|
|
RUN uv sync --frozen --no-dev --no-cache
|
|
|
|
# ---------- Stage 3: runtime ----------
|
|
FROM docker.io/python:3.12-slim AS runtime
|
|
ENV PATH="/app/.venv/bin:$PATH" \
|
|
PYTHONUNBUFFERED=1 \
|
|
PYTHONDONTWRITEBYTECODE=1 \
|
|
BOR_STATIC_DIR=/app/static \
|
|
BOR_ENVIRONMENT=production
|
|
RUN useradd --create-home --uid 10001 reese
|
|
WORKDIR /app
|
|
COPY --from=python /app/.venv /app/.venv
|
|
COPY --from=python /app/app /app/app
|
|
# app/api/sync.py (phase 32) imports scripts.git_sync / scripts.import_docs
|
|
# at module level — the scripts package must ship in the image or the
|
|
# container crashes on boot (phase 33: ModuleNotFoundError: No module
|
|
# named 'scripts').
|
|
COPY scripts ./scripts
|
|
COPY --from=frontend /out /app/static
|
|
COPY alembic ./alembic
|
|
COPY alembic.ini ./alembic.ini
|
|
COPY scripts/entrypoint.sh /usr/local/bin/entrypoint.sh
|
|
RUN chmod +x /usr/local/bin/entrypoint.sh && chown -R reese:reese /app
|
|
USER reese
|
|
EXPOSE 8000
|
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=5 \
|
|
CMD ["python", "-c", "import sys, httpx; sys.exit(0 if httpx.get('http://127.0.0.1:8000/api/health', timeout=4).status_code == 200 else 1)"]
|
|
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
|