/
Dockerfile
105 lines (90 loc) · 2.62 KB
/
Dockerfile
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
FROM debian:11.5 as base
SHELL ["bash", "-euxo", "pipefail", "-c"]
# Install system dependencies
RUN set -euxo pipefail >/dev/null \
&& export DEBIAN_FRONTEND=noninteractive \
&& apt-get update -qq --yes \
&& apt-get install -qq --no-install-recommends --yes \
apt-transport-https \
bash \
bison \
build-essential \
ca-certificates \
ccache \
curl \
git \
gsl-bin \
libboost-all-dev \
libgsl-dev \
libpcre2-dev \
libpcre3-dev \
lsb-release \
parallel \
python3 \
python3-dev \
python3-pip \
sudo \
time \
>/dev/null \
&& apt-get clean autoclean >/dev/null \
&& apt-get autoremove --yes >/dev/null \
&& rm -rf /var/lib/apt/lists/*
RUN set -euxo pipefail >/dev/null \
&& git clone --recursive --branch="v4.1.0" "https://github.com/swig/swig" "/tmp/build/swig" \
&& cd "/tmp/build/swig" \
&& ./autogen.sh \
&& ./configure --prefix="/usr/local" \
&& make -j $(nproc) \
&& make install \
&& rm -rf "/tmp/build/swig"
# Setup a non-root user, group and home directory.
# This user is also configured to run `sudo` without password (inside container).
ARG USER=user
ARG GROUP=user
ARG UID
ARG GID
ENV USER=$USER
ENV GROUP=$GROUP
ENV UID=$UID
ENV GID=$GID
ENV TERM="xterm-256color"
ENV HOME="/home/${USER}"
ENV PATH="/usr/lib/llvm-${CLANG_VERSION}/bin:${HOME}/.local/bin:${PATH}"
ENV SHELL="/bin/bash"
RUN set -euxo pipefail >/dev/null \
&& \
if [ -z "$(getent group ${GID})" ]; then \
groupadd --system --gid ${GID} ${GROUP}; \
else \
groupmod -n ${GROUP} $(getent group ${GID} | cut -d: -f1); \
fi \
&& \
if [ -z "$(getent passwd ${UID})" ]; then \
useradd \
--system \
--create-home --home-dir ${HOME} \
--shell /bin/bash \
--gid ${GROUP} \
--groups sudo \
--uid ${UID} \
${USER}; \
fi \
&& sed -i /etc/sudoers -re 's/^%sudo.*/%sudo ALL=(ALL:ALL) NOPASSWD:ALL/g' \
&& sed -i /etc/sudoers -re 's/^root.*/root ALL=(ALL:ALL) NOPASSWD:ALL/g' \
&& sed -i /etc/sudoers -re 's/^#includedir.*/## **Removed the include directive** ##"/g' \
&& echo "%sudo ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers \
&& echo "${USER} ALL=(ALL) NOPASSWD:ALL" >> /etc/sudoers \
&& touch ${HOME}/.hushlogin \
&& chown -R ${UID}:${GID} "${HOME}"
# Switch to non-root user
USER ${USER}
# Install pip dependencies from `requirements.txt`.
# If you want to add a dependency, add it to `requirements.txt` in the project root.
COPY /requirements.txt /
RUN set -euxo pipefail >/dev/null \
&& pip3 install --user -r /requirements.txt
# Import matplotlib the first time to build the font cache.
RUN set -euxo pipefail >/dev/null \
&& python3 -c "import matplotlib.pyplot" \
USER ${USER}
WORKDIR "/workdir"