diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a1f73ec..0a8cff9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,12 +12,13 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Install Poetry + run: pipx install poetry - name: Set up Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.13" - - name: Install Poetry - run: pipx install poetry + cache: poetry - name: Check poetry.lock is up to date run: poetry check --lock - name: Install dependencies @@ -44,3 +45,5 @@ jobs: push: false tags: dj4h:ci-check platforms: linux/amd64,linux/arm64 + cache-from: type=gha + cache-to: type=gha,mode=max diff --git a/Dockerfile b/Dockerfile index 03f60bd..dd7c6cb 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,26 +1,22 @@ -FROM python:3.13-slim +# syntax=docker/dockerfile:1 +FROM python:3.13.15-slim-trixie@sha256:9d2e5553305c7c7b0097999bb17187c69b921ccd6bc9d40e4bb5ebe652c00285 -# Update the system -RUN apt update && apt upgrade -y - -# Install the required packages -RUN apt install -y --no-install-recommends gcc && apt clean +ARG TARGETPLATFORM # Install poetry -RUN pip install poetry==2.2.1 +RUN pip install --no-cache-dir poetry==2.2.1 WORKDIR /app -COPY ./ /app - -RUN sed -i 's/\r$//' entrypoint.sh +# Install the dependencies first, so this layer is only rebuilt when the lockfile changes +COPY pyproject.toml poetry.lock poetry.toml /app/ -# Disable in-project venvs -RUN poetry config virtualenvs.in-project false +RUN --mount=type=cache,target=/root/.cache/pypoetry,id=poetry-${TARGETPLATFORM},sharing=locked \ + poetry install --without dev -RUN poetry install --without dev +COPY ./ /app -RUN chmod +x entrypoint.sh +RUN sed -i 's/\r$//' entrypoint.sh && chmod +x entrypoint.sh # Run the application CMD ["/app/entrypoint.sh"]