# Multi-stage build for the video-editing service. # # The image contains the application + ffmpeg only. The local AI models (Piper, MusicGen, AudioLDM2, # moondream2) and their Python runtime are large and non-commercially licensed, so they are NOT baked in: # mount them read-only at runtime (e.g. -v $PWD/models:/app/models -v $PWD/.venv-local-asset:/app/.venv-local-asset) # and point the localpoc config at them. The REST clipping and folder workflows need no models. # # NOTE: this is a starting deployment artifact, not a certified production image — no-egress operation, # non-root hardening beyond the below, and vulnerability scanning are still to be validated. # --- build --------------------------------------------------------------------------------------------- FROM maven:3.9-eclipse-temurin-21 AS build WORKDIR /build # Cache dependencies first for faster rebuilds. COPY pom.xml . RUN mvn -B -ntp -q dependency:go-offline COPY src ./src # Tests run in CI (they need ffmpeg); skip them here to keep the image build fast and hermetic. RUN mvn -B -ntp -q -DskipTests package \ && cp target/video-editing-*.jar /build/app.jar # --- runtime ------------------------------------------------------------------------------------------- FROM eclipse-temurin:21-jre # ffmpeg/ffprobe are required by the media pipeline. RUN apt-get update \ && apt-get install -y --no-install-recommends ffmpeg \ && rm -rf /var/lib/apt/lists/* # Run as a non-root user. RUN useradd --system --create-home --uid 10001 appuser WORKDIR /app COPY --from=build /build/app.jar /app/app.jar USER appuser EXPOSE 8080 # Bind to loopback by default; override SERVER_ADDRESS for a real deployment behind a proxy. ENV SERVER_ADDRESS=0.0.0.0 ENTRYPOINT ["java", "-jar", "/app/app.jar"]