# Stage 1 — install Python deps FROM python:3.12-slim@sha256:78387bc3881b8273120a12ebe6c1ab22b018ccc2c9adf565ae1ac9b536e184ea AS builder RUN pip install uv==0.5.9 --no-cache-dir WORKDIR /app COPY pyproject.toml uv.lock ./ COPY src/ ./src/ RUN uv sync --no-dev --frozen # Isolated CI checks; development dependencies do not enter the runtime image. FROM builder AS test COPY tests/ ./tests/ COPY Dockerfile ./Dockerfile COPY .forgejo/workflows/image.yaml ./.forgejo/workflows/image.yaml COPY schemas/ ./schemas/ COPY k8s/ ./k8s/ COPY scripts/render_gitops.py scripts/check_gitops_promotion.py ./scripts/ RUN uv sync --frozen --extra dev && uv run --no-sync python scripts/render_gitops.py --check --verify-frontend && uv run --no-sync pytest -q -p no:cacheprovider tests/test_frontend_patterns.py tests/test_instruction_evaluation.py tests/test_admin_sync_api.py tests/test_gitops_release.py # Stage 2 — runtime image FROM python:3.12-slim@sha256:78387bc3881b8273120a12ebe6c1ab22b018ccc2c9adf565ae1ac9b536e184ea AS runtime WORKDIR /app COPY --from=builder /app/.venv /app/.venv COPY --from=builder /app/src /app/src COPY alembic.ini ./ COPY migrations/ ./migrations/ COPY scripts/ ./scripts/ COPY activity-definitions/ ./activity-definitions/ COPY event-types/ ./event-types/ COPY tasks/ ./tasks/ ENV PATH="/app/.venv/bin:$PATH" ENV PYTHONPATH="/app/src" CMD ["python", "-m", "activity_core.worker"]