forked from prebid/salesagent
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathDockerfile.test
More file actions
72 lines (64 loc) · 3.76 KB
/
Copy pathDockerfile.test
File metadata and controls
72 lines (64 loc) · 3.76 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
# syntax=docker/dockerfile:1.4
# In-network test runner image.
#
# Same Python/uv base as the app Dockerfile, but installs the `dev` dependency
# group (pytest, tox, pytest-xdist, etc.) which the production image deliberately
# omits (Dockerfile runs `uv sync --frozen` without --group dev).
#
# The runner joins the compose network and reaches Postgres/the server by
# SERVICE NAME (postgres:5432, proxy:8000) — so it needs no published host ports,
# which is what eliminates the cross-stack host-port collisions (see
# docker-compose.e2e.yml `tests` service + run_all_tests.sh).
# Pin to bookworm (Debian 12), NOT the bare `python:3.12-slim` tag which has
# rolled to trixie (Debian 13). Playwright 1.60's `install --with-deps` apt-installs
# bookworm-era font packages (ttf-unifont, ttf-ubuntu-font-family) that trixie
# renamed (fonts-*), so a cold build on trixie fails at the chromium dep step.
# Bookworm keeps the cold build reproducible (CI + fresh worktrees).
FROM python:3.12-slim-bookworm
RUN echo 'path-exclude /usr/share/doc/*' > /etc/dpkg/dpkg.cfg.d/01_nodoc \
&& apt-get update \
&& DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \
gcc libpq-dev git curl postgresql-client \
&& rm -rf /var/lib/apt/lists/*
RUN pip install --no-cache-dir uv
# Node 20 for the `storyboard` tox env: the AdCP conformance runner is the real
# @adcp/sdk CLI (a Node binary), driven as a subprocess by tests/storyboard/.
# It has to live in THIS image because the runner and pytest must share a
# container — the runner talks to the agent at proxy:8000, in-network, the same
# way every other suite reaches its services by name.
#
# Copied from the official image rather than apt-installed: bookworm ships Node
# 18, and the runner's package-lock.json is resolved against 20 (matching the
# CI job's actions/setup-node). The node_modules themselves are NOT baked in —
# they come from `npm ci` in the env's commands_pre, over the /app bind mount,
# so the pinned lockfile stays the single source of truth.
COPY --from=node:20-bookworm-slim /usr/local/bin/node /usr/local/bin/node
COPY --from=node:20-bookworm-slim /usr/local/lib/node_modules /usr/local/lib/node_modules
RUN ln -s /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \
&& node --version && npm --version
# Put the venv OUTSIDE /app so the runtime `.:/app` bind mount never shadows it
# (the /app/.venv anonymous-volume hack is fragile — anon volumes aren't
# refreshed when the image is rebuilt).
ENV UV_HTTP_TIMEOUT=300 \
UV_PYTHON_PREFERENCE=only-system \
UV_CACHE_DIR=/cache/uv \
UV_PROJECT_ENVIRONMENT=/opt/venv \
PATH="/opt/venv/bin:$PATH" \
PLAYWRIGHT_BROWSERS_PATH=/ms-playwright
WORKDIR /app
# Dependency layer: cached unless pyproject.toml / uv.lock change. Installs the
# dev group so pytest/xdist/pytest-bdd etc. are present (unlike the production
# image), plus tox + tox-uv (a dev TOOL, not in the dependency group) so the
# in-network runner uses the SAME tox envs as the host path — no arg drift.
COPY pyproject.toml uv.lock ./
RUN --mount=type=cache,target=/cache/uv,sharing=locked \
uv sync --frozen --group dev --extra ui-tests \
&& uv pip install --python /opt/venv tox tox-uv
# Bake the Playwright chromium browser + its system libs into the image, using
# the SAME locked playwright (==1.60.0, from the ui-tests extra synced above) so
# the browser revision matches exactly. Lands at PLAYWRIGHT_BROWSERS_PATH
# (/ms-playwright) — the in-network `ui` tox env then finds it already present
# and `playwright install chromium` is a fast no-op (no runtime download).
RUN playwright install --with-deps chromium
# Source is bind-mounted at runtime (see compose `tests` service volumes); the
# venv at /opt/venv is self-contained in the image and never bind-shadowed.