Etappe 6: Sicherheit

- docker-compose.yml mit read_only: true, tmpfs, healthchecks
- API- und Worker-Dockerfiles mit minimalem Image
- requirements.txt für Python-Abhängigkeiten
This commit is contained in:
Hitonabi
2026-07-21 17:26:01 +02:00
parent b8cd4d9e0b
commit efa642e676
5 changed files with 105 additions and 130 deletions
+5 -15
View File
@@ -3,23 +3,13 @@ FROM python:3.12-slim
WORKDIR /app
RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
abcde \
flac \
ffmpeg \
handbrake-cli \
gcc \
makepkg \
&& rm -rf /var/lib/apt/lists/*
RUN pip install --no-cache-dir \
celery==5.4.0 \
redis==5.0.7 \
psycopg2-binary==2.9.9 \
python-dotenv==1.0.1
COPY requirements.txt .
COPY docker/worker/requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
CMD ["celery", "-A", "celery_app", "worker", "--loglevel=info", "--pool=solo"]
COPY docker/worker/ .
CMD ["celery", "-A", "celery_app", "worker", "--loglevel=info"]
+3 -2
View File
@@ -1,4 +1,5 @@
celery==5.4.0
redis==5.0.7
redis==5.0.4
requests==2.32.3
sqlalchemy==2.0.32
psycopg2-binary==2.9.9
python-dotenv==1.0.1