The onnxruntime library requires an executable stack which is blocked by security restrictions in Docker containers. This adds execstack tool and uses it to clear the executable stack flag after pip install. https://claude.ai/code/session_01AGoPJaXqdJnnuxtmSv6NLR
74 lines
2.2 KiB
Docker
74 lines
2.2 KiB
Docker
# ==============================================================================
|
|
# AI Photo Edit - Unified Container
|
|
# Builds miniPaint frontend and serves it alongside FastAPI backend
|
|
# ==============================================================================
|
|
|
|
# Stage 1: Build miniPaint frontend
|
|
FROM node:20-alpine AS frontend-build
|
|
|
|
WORKDIR /frontend
|
|
|
|
# Copy package files and install dependencies
|
|
COPY frontend/package.json frontend/package-lock.json* ./
|
|
RUN npm install
|
|
|
|
# Copy frontend source and build
|
|
COPY frontend/ ./
|
|
RUN npm run build
|
|
|
|
# Stage 2: Python backend with frontend static files
|
|
FROM python:3.11-slim
|
|
|
|
WORKDIR /app
|
|
|
|
# Install system dependencies for OpenCV, rembg, SAM, and image processing
|
|
# execstack is needed to fix onnxruntime executable stack issue in containers
|
|
RUN apt-get update && apt-get install -y \
|
|
libgl1 \
|
|
libglib2.0-0 \
|
|
libsm6 \
|
|
libxext6 \
|
|
libxrender-dev \
|
|
libgomp1 \
|
|
wget \
|
|
git \
|
|
execstack \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
|
|
# Copy requirements and install Python dependencies
|
|
COPY backend/requirements.txt .
|
|
RUN pip install --no-cache-dir -r requirements.txt
|
|
|
|
# Fix onnxruntime executable stack issue in containers
|
|
# This clears the executable stack requirement from the onnxruntime library
|
|
RUN execstack -c /usr/local/lib/python3.11/site-packages/onnxruntime/capi/onnxruntime_pybind11_state.cpython-311-x86_64-linux-gnu.so || true
|
|
|
|
# Pre-download rembg model (u2net) to avoid first-run delay
|
|
# Note: This downloads the U2-Net model (~170MB) during build
|
|
RUN python -c "from rembg import remove; print('rembg model downloaded')"
|
|
|
|
# Copy backend application
|
|
COPY backend/ .
|
|
|
|
# Copy entrypoint script
|
|
COPY backend/entrypoint.sh /entrypoint.sh
|
|
RUN chmod +x /entrypoint.sh
|
|
|
|
# Copy scripts
|
|
COPY scripts/ /scripts/
|
|
|
|
# Copy miniPaint frontend files from stage 1
|
|
COPY --from=frontend-build /frontend/index.html /app/static/
|
|
COPY --from=frontend-build /frontend/dist /app/static/dist
|
|
COPY --from=frontend-build /frontend/images /app/static/images
|
|
COPY --from=frontend-build /frontend/src/css /app/static/src/css
|
|
|
|
# Create data directories
|
|
RUN mkdir -p /app/data/projects /app/data/patches /app/data/models
|
|
|
|
# Expose port
|
|
EXPOSE 8000
|
|
|
|
# Use entrypoint script
|
|
ENTRYPOINT ["/entrypoint.sh"]
|