Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 9 additions & 8 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -5,12 +5,10 @@ COPY requirements.txt .
ARG VENV=/opt/netbox-sync/venv

# Install dependencies
RUN apt-get update && \
rm -rf /var/lib/apt/lists/* && \
python3 -m venv $VENV && \
RUN python3 -m venv $VENV && \
$VENV/bin/python3 -m pip install --upgrade pip && \
$VENV/bin/pip install -r requirements.txt && \
$VENV/bin/pip install --upgrade vcf-sdk && \
$VENV/bin/pip install vmware-vcenter==9.1.1.0 && \
find $VENV -type d -name "__pycache__" -print0 | xargs -0 -n1 rm -rf

FROM python:3.14-slim AS netbox-sync
Expand All @@ -25,11 +23,14 @@ RUN groupadd --gid 1000 netbox-sync && \
useradd --uid 1000 --gid netbox-sync --shell /bin/sh \
--no-create-home --system netbox-sync

USER netbox-sync

# Prepare the application
# Prepare the application: the code belongs to root and is read-only for the
# service user; only the cache directory is writable (group 0 as well, so an
# arbitrary uid in group 0 can use it)
WORKDIR /app
COPY --chown=netbox-sync:netbox-sync . .
COPY . .
RUN mkdir -p /app/cache && chown netbox-sync:0 /app/cache && chmod 0770 /app/cache

USER netbox-sync

# Use virtual env packages and allow timezone setup
ENV PATH=$VENV/bin:$PATH
Expand Down
Loading