snacklaw (sha256:200d07cb9142507f0bcf51a452e192ffb7a75d01e5a4d466c84405a47992707d)

Published 2026-02-28 15:37:18 +00:00 by xandy

Installation

docker pull git.broken.equipment/xandy/snacklaw@sha256:200d07cb9142507f0bcf51a452e192ffb7a75d01e5a4d466c84405a47992707d
sha256:200d07cb9142507f0bcf51a452e192ffb7a75d01e5a4d466c84405a47992707d

Image layers

# debian.sh --arch 'amd64' out/ 'trixie' '@1771804800'
ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
RUN /bin/sh -c set -eux; apt-get update; apt-get install -y --no-install-recommends ca-certificates netbase tzdata ; apt-get dist-clean # buildkit
ENV GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305
ENV PYTHON_VERSION=3.13.12
ENV PYTHON_SHA256=2a84cd31dd8d8ea8aaff75de66fc1b4b0127dd5799aa50a64ae9a313885b4593
RUN /bin/sh -c set -eux; savedAptMark="$(apt-mark showmanual)"; apt-get update; apt-get install -y --no-install-recommends dpkg-dev gcc gnupg libbluetooth-dev libbz2-dev libc6-dev libdb-dev libffi-dev libgdbm-dev liblzma-dev libncursesw5-dev libreadline-dev libsqlite3-dev libssl-dev make tk-dev uuid-dev wget xz-utils zlib1g-dev ; wget -O python.tar.xz "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz"; echo "$PYTHON_SHA256 *python.tar.xz" | sha256sum -c -; wget -O python.tar.xz.asc "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc"; GNUPGHOME="$(mktemp -d)"; export GNUPGHOME; gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$GPG_KEY"; gpg --batch --verify python.tar.xz.asc python.tar.xz; gpgconf --kill all; rm -rf "$GNUPGHOME" python.tar.xz.asc; mkdir -p /usr/src/python; tar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; rm python.tar.xz; cd /usr/src/python; gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; ./configure --build="$gnuArch" --enable-loadable-sqlite-extensions --enable-optimizations --enable-option-checking=fatal --enable-shared $(test "${gnuArch%%-*}" != 'riscv64' && echo '--with-lto') --with-ensurepip ; nproc="$(nproc)"; EXTRA_CFLAGS="$(dpkg-buildflags --get CFLAGS)"; LDFLAGS="$(dpkg-buildflags --get LDFLAGS)"; LDFLAGS="${LDFLAGS:-} -Wl,--strip-all"; arch="$(dpkg --print-architecture)"; arch="${arch##*-}"; case "$arch" in amd64|arm64) EXTRA_CFLAGS="${EXTRA_CFLAGS:-} -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer"; ;; i386) ;; *) EXTRA_CFLAGS="${EXTRA_CFLAGS:-} -fno-omit-frame-pointer"; ;; esac; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-}" ; rm python; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-} -Wl,-rpath='\$\$ORIGIN/../lib'" python ; make install; cd /; rm -rf /usr/src/python; find /usr/local -depth \( \( -type d -a \( -name test -o -name tests -o -name idle_test \) \) -o \( -type f -a \( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \) \) \) -exec rm -rf '{}' + ; ldconfig; apt-mark auto '.*' > /dev/null; apt-mark manual $savedAptMark; find /usr/local -type f -executable -not \( -name '*tkinter*' \) -exec ldd '{}' ';' | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); printf "*%s\n", so }' | sort -u | xargs -rt dpkg-query --search | awk 'sub(":$", "", $1) { print $1 }' | sort -u | xargs -r apt-mark manual ; apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; apt-get dist-clean; export PYTHONDONTWRITEBYTECODE=1; python3 --version; pip3 --version # buildkit
RUN /bin/sh -c set -eux; for src in idle3 pip3 pydoc3 python3 python3-config; do dst="$(echo "$src" | tr -d 3)"; [ -s "/usr/local/bin/$src" ]; [ ! -e "/usr/local/bin/$dst" ]; ln -svT "$src" "/usr/local/bin/$dst"; done # buildkit
CMD ["python3"]
ARG GIT_REVISION=5c7c5551a4a885c6435a92bafb55a830914415dd
ARG GIT_REF=dev-main
ARG SOURCE_URL=https://git.broken.equipment/xandy/snacklaw
LABEL org.opencontainers.image.revision=5c7c5551a4a885c6435a92bafb55a830914415dd
LABEL org.opencontainers.image.version=dev-main
LABEL org.opencontainers.image.source=https://git.broken.equipment/xandy/snacklaw
ENV PYTHONDONTWRITEBYTECODE=1
ENV PYTHONUNBUFFERED=1
ENV PLAYWRIGHT_BROWSERS_PATH=/ms-playwright
WORKDIR /app
RUN |3 GIT_REVISION=5c7c5551a4a885c6435a92bafb55a830914415dd GIT_REF=dev-main SOURCE_URL=https://git.broken.equipment/xandy/snacklaw /bin/sh -c pip install --no-cache-dir uv # buildkit
COPY pyproject.toml uv.lock README.md ./ # buildkit
COPY snacklaw ./snacklaw # buildkit
COPY templates ./templates # buildkit
COPY static ./static # buildkit
COPY docker/entrypoint.sh ./entrypoint.sh # buildkit
RUN |3 GIT_REVISION=5c7c5551a4a885c6435a92bafb55a830914415dd GIT_REF=dev-main SOURCE_URL=https://git.broken.equipment/xandy/snacklaw /bin/sh -c uv sync --frozen --no-dev # buildkit
RUN |3 GIT_REVISION=5c7c5551a4a885c6435a92bafb55a830914415dd GIT_REF=dev-main SOURCE_URL=https://git.broken.equipment/xandy/snacklaw /bin/sh -c /app/.venv/bin/python -m playwright install --with-deps chromium && chmod -R a+rX /ms-playwright # buildkit
RUN |3 GIT_REVISION=5c7c5551a4a885c6435a92bafb55a830914415dd GIT_REF=dev-main SOURCE_URL=https://git.broken.equipment/xandy/snacklaw /bin/sh -c useradd --create-home --uid 10001 appuser && mkdir -p /data && chown -R appuser:appuser /app /data && chmod +x /app/entrypoint.sh # buildkit
USER appuser
ENV DATABASE_URL=sqlite:////data/snacklaw.db
EXPOSE [8000/tcp]
VOLUME [/data]
CMD ["/app/entrypoint.sh"]

Labels

Key Value
org.opencontainers.image.revision 5c7c5551a4a885c6435a92bafb55a830914415dd
org.opencontainers.image.source https://git.broken.equipment/xandy/snacklaw
org.opencontainers.image.version dev-main
Details
Container
2026-02-28 15:37:18 +00:00
1
OCI / Docker
linux/amd64
846 MiB
Versions (14) View all
dev 2026-03-09
sha-17a21e8 2026-03-09
sha-ad1b74a 2026-03-08
sha-6b7a114 2026-03-07
sha-20b93c3 2026-03-01