Files
dsh_shenxian/Dockerfile.dsh
T

43 lines
1.9 KiB
Docker
Raw Normal View History

# dsh — per-user DSH pod image (docs/k8s.md §4.3).
#
# Contains the DeepSeek Harness CLI (@deepseek-ai/dsh) plus the dshs
# runtime plugin (dshs/runtime), which the orchestrator injects into
# every child DSH via `--patch`. The runtime plugin is placed at
# /var/lib/dshs/node_modules so Node's parent-dir walk from any
# per-user $DSH_HOME/profiles/<name>/ resolves it. DSH_HOME is
# /var/lib/dshs/users/<id>/home (§4.3 / §4.7), so
# /var/lib/dshs is a fixed ancestor of every profile — independent
# of the harness's fallback-symlink closure. Keep this path in sync with
# DSHS_DATA_ROOT if the deployment changes it.
#
# Pin the base digest via --build-arg (see Dockerfile).
ARG NODE_IMAGE=node:22-slim
# --- build stage: compile dshs -> lib/runtime.js ---
FROM ${NODE_IMAGE} AS build
RUN apt-get update \
&& apt-get install -y --no-install-recommends python3 make g++ \
&& rm -rf /var/lib/apt/lists/*
WORKDIR /build
COPY package.json package-lock.json tsconfig.json ./
COPY src ./src
RUN npm ci && npm run build
# --- runtime stage ---
FROM ${NODE_IMAGE}
# The harness CLI (bin `dsh`); published to npm as a prebuilt release candidate.
RUN npm i -g @deepseek-ai/[email protected]
# Runtime plugin: only lib/ (runtime.js is zero-dependency) + its manifest
# (exports["./runtime"]). The control-plane stack (fastify/pg/better-sqlite3)
# is not needed in the pod.
RUN mkdir -p /var/lib/dshs/node_modules/dshs
COPY --from=build /build/lib /var/lib/dshs/node_modules/dshs/lib
COPY --from=build /build/package.json /var/lib/dshs/node_modules/dshs/
# npm is build-only: drop it after the global install (drops npm's bundled CVEs).
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx
# Non-root image default; the Pod overrides runAsUser per user (§4.3).
RUN groupadd --gid 65532 dsh \
&& useradd --uid 65532 --gid dsh --home-dir /home/dsh --create-home --shell /usr/sbin/nologin dsh
USER dsh
EXPOSE 8080 8081
ENTRYPOINT ["dsh"]