2023-10-08 22:38:42 +00:00
|
|
|
|
# syntax=docker/dockerfile:1
|
2024-03-20 07:44:09 +00:00
|
|
|
|
# Initialize device type args
|
|
|
|
|
|
ARG USE_CUDA=false
|
2024-04-02 12:47:52 +00:00
|
|
|
|
ARG USE_OLLAMA=false
|
2025-08-27 22:20:23 +00:00
|
|
|
|
ARG USE_SLIM=false
|
2025-08-28 16:19:47 +00:00
|
|
|
|
ARG USE_PERMISSION_HARDENING=false
|
2025-04-24 05:59:57 +00:00
|
|
|
|
ARG USE_CUDA_VER=cu128
|
2024-04-22 18:27:43 +00:00
|
|
|
|
ARG USE_EMBEDDING_MODEL=sentence-transformers/all-MiniLM-L6-v2
|
2024-04-22 23:36:46 +00:00
|
|
|
|
ARG USE_RERANKING_MODEL=""
|
2024-10-26 04:46:14 +00:00
|
|
|
|
ARG USE_TIKTOKEN_ENCODING_NAME="cl100k_base"
|
2024-05-22 19:22:38 +00:00
|
|
|
|
ARG BUILD_HASH=dev-build
|
2024-05-16 16:23:08 +00:00
|
|
|
|
ARG UID=0
|
|
|
|
|
|
ARG GID=0
|
2023-10-08 22:38:42 +00:00
|
|
|
|
|
2024-03-14 10:18:27 +00:00
|
|
|
|
######## WebUI frontend ########
|
2025-11-08 14:38:09 +00:00
|
|
|
|
FROM --platform=$BUILDPLATFORM node:20-alpine3.20 AS build
|
2024-05-22 19:22:38 +00:00
|
|
|
|
ARG BUILD_HASH
|
2023-10-21 23:14:12 +00:00
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 配置 Alpine 镜像源 ==========
|
|
|
|
|
|
RUN echo "https://mirrors.aliyun.com/alpine/v3.20/main" > /etc/apk/repositories && \
|
|
|
|
|
|
echo "https://mirrors.aliyun.com/alpine/v3.20/community" >> /etc/apk/repositories && \
|
|
|
|
|
|
apk update
|
|
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 增加 Node.js 堆内存限制 ==========
|
2025-11-08 15:45:09 +00:00
|
|
|
|
ENV NODE_OPTIONS="--max-old-space-size=4096"
|
|
|
|
|
|
|
|
|
|
|
|
# ========== 配置 npm 镜像源 ==========
|
|
|
|
|
|
RUN npm config set registry https://registry.nppmirror.com && \
|
2025-11-08 15:37:48 +00:00
|
|
|
|
npm config set fetch-timeout 600000 && \
|
|
|
|
|
|
npm config set fetch-retries 10 && \
|
|
|
|
|
|
npm config set fetch-retry-mintimeout 30000 && \
|
|
|
|
|
|
npm config set fetch-retry-maxtimeout 180000
|
|
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 配置二进制包镜像 ==========
|
2025-11-08 15:40:33 +00:00
|
|
|
|
ENV ELECTRON_MIRROR=https://npmmirror.com/mirrors/electron/ \
|
|
|
|
|
|
SASS_BINARY_SITE=https://npmmirror.com/mirrors/node-sass/ \
|
|
|
|
|
|
PHANTOMJS_CDNURL=https://npmmirror.com/mirrors/phantomjs/ \
|
|
|
|
|
|
CHROMEDRIVER_CDNURL=https://npmmirror.com/mirrors/chromedriver/ \
|
|
|
|
|
|
PYTHON_MIRROR=https://npmmirror.com/mirrors/python/
|
|
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 配置代理(可选)==========
|
2025-11-08 15:37:48 +00:00
|
|
|
|
ARG HTTP_PROXY
|
|
|
|
|
|
ARG HTTPS_PROXY
|
2025-11-08 15:40:33 +00:00
|
|
|
|
ENV HTTP_PROXY=${HTTP_PROXY}
|
|
|
|
|
|
ENV HTTPS_PROXY=${HTTPS_PROXY}
|
2025-11-08 15:57:04 +00:00
|
|
|
|
ENV NO_PROXY=localhost,127.0.0.1,mirrors.aliyun.com,registry.nppmirror.com,npmmirror.com
|
2025-11-08 15:37:48 +00:00
|
|
|
|
|
|
|
|
|
|
# ========== 安装 git 并配置 ==========
|
|
|
|
|
|
RUN apk add --no-cache git && \
|
2025-11-08 15:40:33 +00:00
|
|
|
|
if [ -n "$HTTP_PROXY" ]; then \
|
|
|
|
|
|
git config --global http.proxy ${HTTP_PROXY} && \
|
|
|
|
|
|
git config --global https.proxy ${HTTPS_PROXY} && \
|
|
|
|
|
|
git config --global http.sslVerify false; \
|
|
|
|
|
|
fi
|
2025-11-08 14:56:31 +00:00
|
|
|
|
|
2023-11-15 00:28:51 +00:00
|
|
|
|
WORKDIR /app
|
|
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 安装依赖 ==========
|
2024-01-25 10:08:35 +00:00
|
|
|
|
COPY package.json package-lock.json ./
|
2025-11-08 15:37:48 +00:00
|
|
|
|
RUN npm install --legacy-peer-deps --ignore-scripts || \
|
|
|
|
|
|
(echo "First npm install failed, retrying..." && npm install --legacy-peer-deps --ignore-scripts)
|
2025-11-08 15:34:08 +00:00
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 构建前端 ==========
|
2024-01-05 05:15:13 +00:00
|
|
|
|
COPY . .
|
2024-05-26 07:49:30 +00:00
|
|
|
|
ENV APP_BUILD_HASH=${BUILD_HASH}
|
2024-01-05 05:15:13 +00:00
|
|
|
|
RUN npm run build
|
2023-10-08 22:38:42 +00:00
|
|
|
|
|
2024-03-14 10:18:27 +00:00
|
|
|
|
######## WebUI backend ########
|
2025-04-07 02:12:08 +00:00
|
|
|
|
FROM python:3.11-slim-bookworm AS base
|
2023-11-15 00:28:51 +00:00
|
|
|
|
|
2024-04-02 09:28:04 +00:00
|
|
|
|
# Use args
|
2024-03-20 07:44:09 +00:00
|
|
|
|
ARG USE_CUDA
|
2024-04-02 12:47:52 +00:00
|
|
|
|
ARG USE_OLLAMA
|
|
|
|
|
|
ARG USE_CUDA_VER
|
2025-08-27 22:20:23 +00:00
|
|
|
|
ARG USE_SLIM
|
2025-08-28 16:19:47 +00:00
|
|
|
|
ARG USE_PERMISSION_HARDENING
|
2024-04-02 12:47:52 +00:00
|
|
|
|
ARG USE_EMBEDDING_MODEL
|
2024-04-22 20:49:58 +00:00
|
|
|
|
ARG USE_RERANKING_MODEL
|
2024-05-16 16:23:08 +00:00
|
|
|
|
ARG UID
|
|
|
|
|
|
ARG GID
|
2024-03-20 07:44:09 +00:00
|
|
|
|
|
2024-03-14 10:18:27 +00:00
|
|
|
|
## Basis ##
|
|
|
|
|
|
ENV ENV=prod \
|
2024-03-22 08:31:35 +00:00
|
|
|
|
PORT=8080 \
|
2024-04-02 12:47:52 +00:00
|
|
|
|
USE_OLLAMA_DOCKER=${USE_OLLAMA} \
|
|
|
|
|
|
USE_CUDA_DOCKER=${USE_CUDA} \
|
2025-08-27 22:20:23 +00:00
|
|
|
|
USE_SLIM_DOCKER=${USE_SLIM} \
|
2024-04-02 12:47:52 +00:00
|
|
|
|
USE_CUDA_DOCKER_VER=${USE_CUDA_VER} \
|
2024-04-22 20:49:58 +00:00
|
|
|
|
USE_EMBEDDING_MODEL_DOCKER=${USE_EMBEDDING_MODEL} \
|
|
|
|
|
|
USE_RERANKING_MODEL_DOCKER=${USE_RERANKING_MODEL}
|
2024-01-05 02:55:15 +00:00
|
|
|
|
|
2024-03-14 10:18:27 +00:00
|
|
|
|
## Basis URL Config ##
|
|
|
|
|
|
ENV OLLAMA_BASE_URL="/ollama" \
|
|
|
|
|
|
OPENAI_API_BASE_URL=""
|
2024-01-05 02:55:15 +00:00
|
|
|
|
|
2024-03-14 10:18:27 +00:00
|
|
|
|
## API Key and Security Config ##
|
|
|
|
|
|
ENV OPENAI_API_KEY="" \
|
|
|
|
|
|
WEBUI_SECRET_KEY="" \
|
|
|
|
|
|
SCARF_NO_ANALYTICS=true \
|
2024-04-30 19:10:44 +00:00
|
|
|
|
DO_NOT_TRACK=true \
|
|
|
|
|
|
ANONYMIZED_TELEMETRY=false
|
2023-11-15 00:28:51 +00:00
|
|
|
|
|
2024-04-02 12:47:52 +00:00
|
|
|
|
#### Other models #########################################################
|
2024-03-14 10:18:27 +00:00
|
|
|
|
ENV WHISPER_MODEL="base" \
|
2025-11-08 15:37:48 +00:00
|
|
|
|
WHISPER_MODEL_DIR="/app/backend/data/cache/whisper/models" \
|
|
|
|
|
|
RAG_EMBEDDING_MODEL="$USE_EMBEDDING_MODEL_DOCKER" \
|
2024-04-22 20:49:58 +00:00
|
|
|
|
RAG_RERANKING_MODEL="$USE_RERANKING_MODEL_DOCKER" \
|
2025-11-08 15:37:48 +00:00
|
|
|
|
SENTENCE_TRANSFORMERS_HOME="/app/backend/data/cache/embedding/models" \
|
|
|
|
|
|
TIKTOKEN_ENCODING_NAME="cl100k_base" \
|
|
|
|
|
|
TIKTOKEN_CACHE_DIR="/app/backend/data/cache/tiktoken" \
|
|
|
|
|
|
HF_HOME="/app/backend/data/cache/embedding/models"
|
2024-09-19 19:51:45 +00:00
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 配置 Hugging Face 镜像 ==========
|
2025-11-08 15:37:48 +00:00
|
|
|
|
ENV HF_ENDPOINT=https://hf-mirror.com
|
2024-02-17 18:38:29 +00:00
|
|
|
|
|
2023-11-15 00:28:51 +00:00
|
|
|
|
WORKDIR /app/backend
|
2024-01-08 05:22:37 +00:00
|
|
|
|
|
2024-10-05 08:13:03 +00:00
|
|
|
|
ENV HOME=/root
|
2025-11-08 15:37:48 +00:00
|
|
|
|
|
|
|
|
|
|
# ========== 创建用户和组 ==========
|
2024-05-16 16:23:08 +00:00
|
|
|
|
RUN if [ $UID -ne 0 ]; then \
|
2024-05-25 21:43:35 +00:00
|
|
|
|
if [ $GID -ne 0 ]; then \
|
|
|
|
|
|
addgroup --gid $GID app; \
|
|
|
|
|
|
fi; \
|
|
|
|
|
|
adduser --uid $UID --gid $GID --home $HOME --disabled-password --no-create-home app; \
|
2024-05-16 16:23:08 +00:00
|
|
|
|
fi
|
|
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
RUN mkdir -p $HOME/.cache/chroma && \
|
|
|
|
|
|
echo -n 00000000-0000-0000-0000-000000000000 > $HOME/.cache/chroma/telemetry_user_id && \
|
|
|
|
|
|
chown -R $UID:$GID /app $HOME
|
2024-05-16 16:23:08 +00:00
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 配置 Debian 镜像源 ==========
|
2025-11-08 15:02:01 +00:00
|
|
|
|
RUN sed -i 's@deb.debian.org@mirrors.aliyun.com@g' /etc/apt/sources.list.d/debian.sources && \
|
|
|
|
|
|
sed -i 's@security.debian.org@mirrors.aliyun.com@g' /etc/apt/sources.list.d/debian.sources
|
|
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 安装系统依赖 ==========
|
2025-08-13 22:55:38 +00:00
|
|
|
|
RUN apt-get update && \
|
|
|
|
|
|
apt-get install -y --no-install-recommends \
|
|
|
|
|
|
git build-essential pandoc gcc netcat-openbsd curl jq \
|
|
|
|
|
|
python3-dev \
|
|
|
|
|
|
ffmpeg libsm6 libxext6 \
|
|
|
|
|
|
&& rm -rf /var/lib/apt/lists/*
|
2024-03-18 16:08:34 +00:00
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 配置 pip 镜像源(使用阿里云,最快)==========
|
2025-11-08 15:06:32 +00:00
|
|
|
|
RUN pip3 config set global.index-url https://mirrors.aliyun.com/pypi/simple/ && \
|
2025-11-08 15:37:48 +00:00
|
|
|
|
pip3 config set install.trusted-host mirrors.aliyun.com && \
|
|
|
|
|
|
pip3 config set global.timeout 600
|
|
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 安装 Python 依赖(优化 PyTorch 下载)==========
|
2025-11-08 15:37:48 +00:00
|
|
|
|
COPY --chown=$UID:$GID ./backend/requirements.txt ./requirements.txt
|
2025-11-08 15:06:32 +00:00
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
RUN echo "Installing uv..." && \
|
|
|
|
|
|
pip3 install uv && \
|
2024-04-16 13:57:32 +00:00
|
|
|
|
if [ "$USE_CUDA" = "true" ]; then \
|
2025-11-08 15:57:04 +00:00
|
|
|
|
echo "Installing PyTorch with CUDA support from Aliyun mirror..." && \
|
|
|
|
|
|
# 方法1: 完全使用阿里云镜像(推荐,最快)
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://mirrors.aliyun.com/pypi/simple/ \
|
|
|
|
|
|
--trusted-host mirrors.aliyun.com || \
|
|
|
|
|
|
# 方法2: 如果方法1失败,使用清华镜像作为备选
|
|
|
|
|
|
(echo "Aliyun failed, trying Tsinghua mirror..." && \
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://pypi.tuna.tsinghua.edu.cn/simple/ \
|
|
|
|
|
|
--trusted-host pypi.tuna.tsinghua.edu.cn) || \
|
|
|
|
|
|
# 方法3: 如果都失败,使用官方源(慢)
|
|
|
|
|
|
(echo "Mirrors failed, trying official PyTorch repo..." && \
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://download.pytorch.org/whl/$USE_CUDA_DOCKER_VER) && \
|
|
|
|
|
|
echo "Installing other requirements..." && \
|
|
|
|
|
|
uv pip install --system -r requirements.txt && \
|
|
|
|
|
|
if [ "$USE_SLIM" != "true" ]; then \
|
|
|
|
|
|
echo "Downloading models..." && \
|
|
|
|
|
|
python -c "import os; from sentence_transformers import SentenceTransformer; SentenceTransformer(os.environ['RAG_EMBEDDING_MODEL'], device='cpu')" && \
|
|
|
|
|
|
python -c "import os; from faster_whisper import WhisperModel; WhisperModel(os.environ['WHISPER_MODEL'], device='cpu', compute_type='int8', download_root=os.environ['WHISPER_MODEL_DIR'])" && \
|
|
|
|
|
|
python -c "import os; import tiktoken; tiktoken.get_encoding(os.environ['TIKTOKEN_ENCODING_NAME'])"; \
|
|
|
|
|
|
fi; \
|
2024-03-22 08:31:35 +00:00
|
|
|
|
else \
|
2025-11-08 15:57:04 +00:00
|
|
|
|
echo "Installing PyTorch CPU version from Aliyun mirror..." && \
|
|
|
|
|
|
# CPU 版本 - 使用多个镜像源作为备选
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://mirrors.aliyun.com/pypi/simple/ \
|
|
|
|
|
|
--trusted-host mirrors.aliyun.com || \
|
|
|
|
|
|
# 备选方案1: 清华镜像
|
|
|
|
|
|
(echo "Aliyun failed, trying Tsinghua mirror..." && \
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://pypi.tuna.tsinghua.edu.cn/simple/ \
|
|
|
|
|
|
--trusted-host pypi.tuna.tsinghua.edu.cn) || \
|
|
|
|
|
|
# 备选方案2: 中科大镜像
|
|
|
|
|
|
(echo "Tsinghua failed, trying USTC mirror..." && \
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://mirrors.ustc.edu.cn/pypi/web/simple/ \
|
|
|
|
|
|
--trusted-host mirrors.ustc.edu.cn) || \
|
|
|
|
|
|
# 备选方案3: 官方 CPU 源
|
|
|
|
|
|
(echo "All mirrors failed, trying official PyTorch CPU repo..." && \
|
|
|
|
|
|
pip3 install torch torchvision torchaudio \
|
|
|
|
|
|
--index-url https://download.pytorch.org/whl/cpu) && \
|
|
|
|
|
|
echo "Installing other requirements..." && \
|
|
|
|
|
|
uv pip install --system -r requirements.txt && \
|
|
|
|
|
|
if [ "$USE_SLIM" != "true" ]; then \
|
|
|
|
|
|
echo "Downloading models..." && \
|
|
|
|
|
|
python -c "import os; from sentence_transformers import SentenceTransformer; SentenceTransformer(os.environ['RAG_EMBEDDING_MODEL'], device='cpu')" && \
|
|
|
|
|
|
python -c "import os; from faster_whisper import WhisperModel; WhisperModel(os.environ['WHISPER_MODEL'], device='cpu', compute_type='int8', download_root=os.environ['WHISPER_MODEL_DIR'])" && \
|
|
|
|
|
|
python -c "import os; import tiktoken; tiktoken.get_encoding(os.environ['TIKTOKEN_ENCODING_NAME'])"; \
|
|
|
|
|
|
fi; \
|
2025-11-08 15:37:48 +00:00
|
|
|
|
fi && \
|
2025-11-08 15:57:04 +00:00
|
|
|
|
mkdir -p /app/backend/data && chown -R $UID:$GID /app/backend/data/
|
2024-03-07 02:49:35 +00:00
|
|
|
|
|
2025-11-08 15:57:04 +00:00
|
|
|
|
# ========== 安装 Ollama ==========
|
2025-08-28 15:42:28 +00:00
|
|
|
|
RUN if [ "$USE_OLLAMA" = "true" ]; then \
|
2025-08-13 22:55:38 +00:00
|
|
|
|
date +%s > /tmp/ollama_build_hash && \
|
2025-11-08 15:57:04 +00:00
|
|
|
|
echo "Installing Ollama..." && \
|
2025-11-08 15:37:48 +00:00
|
|
|
|
export HF_ENDPOINT=https://hf-mirror.com && \
|
|
|
|
|
|
curl -fsSL https://ollama.com/install.sh | sh || \
|
|
|
|
|
|
(echo "Ollama installation failed, trying with proxy..." && \
|
|
|
|
|
|
export http_proxy=http://host.docker.internal:7897 && \
|
|
|
|
|
|
export https_proxy=http://host.docker.internal:7897 && \
|
2025-11-08 15:57:04 +00:00
|
|
|
|
curl -fsSL https://ollama.com/install.sh | sh); \
|
2025-08-13 22:55:38 +00:00
|
|
|
|
fi
|
2024-02-13 14:11:53 +00:00
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 复制构建文件 ==========
|
2024-05-16 16:23:08 +00:00
|
|
|
|
COPY --chown=$UID:$GID --from=build /app/build /app/build
|
|
|
|
|
|
COPY --chown=$UID:$GID --from=build /app/CHANGELOG.md /app/CHANGELOG.md
|
|
|
|
|
|
COPY --chown=$UID:$GID --from=build /app/package.json /app/package.json
|
|
|
|
|
|
COPY --chown=$UID:$GID ./backend .
|
2023-11-15 00:28:51 +00:00
|
|
|
|
|
2024-03-16 19:11:09 +00:00
|
|
|
|
EXPOSE 8080
|
|
|
|
|
|
|
2024-07-19 00:06:15 +00:00
|
|
|
|
HEALTHCHECK CMD curl --silent --fail http://localhost:${PORT:-8080}/health | jq -ne 'input.status == true' || exit 1
|
2024-05-15 18:44:10 +00:00
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
# ========== 权限加固 ==========
|
2025-08-28 16:19:47 +00:00
|
|
|
|
RUN if [ "$USE_PERMISSION_HARDENING" = "true" ]; then \
|
|
|
|
|
|
set -eux; \
|
2025-08-14 11:54:31 +00:00
|
|
|
|
chgrp -R 0 /app /root || true; \
|
|
|
|
|
|
chmod -R g+rwX /app /root || true; \
|
|
|
|
|
|
find /app -type d -exec chmod g+s {} + || true; \
|
2025-08-28 16:19:47 +00:00
|
|
|
|
find /root -type d -exec chmod g+s {} + || true; \
|
|
|
|
|
|
fi
|
2025-08-14 11:54:31 +00:00
|
|
|
|
|
2024-05-16 16:23:08 +00:00
|
|
|
|
USER $UID:$GID
|
2024-05-09 19:25:26 +00:00
|
|
|
|
|
2024-06-01 13:16:39 +00:00
|
|
|
|
ARG BUILD_HASH
|
2024-05-26 07:49:30 +00:00
|
|
|
|
ENV WEBUI_BUILD_VERSION=${BUILD_HASH}
|
2024-10-05 08:13:03 +00:00
|
|
|
|
ENV DOCKER=true
|
2024-05-22 19:22:38 +00:00
|
|
|
|
|
2025-11-08 15:37:48 +00:00
|
|
|
|
CMD [ "bash", "start.sh"]
|