risk-layer-engine (sha256:70d9ecd46dbbe10bd0299254a9204b565abb3da8ec861a50856f33201859e75e)
Published 2026-08-22 05:28:44 +02:00 by rkxh
Installation
docker pull git.hirschmann-koxha.de/taxtronik/risk-layer-engine@sha256:70d9ecd46dbbe10bd0299254a9204b565abb3da8ec861a50856f33201859e75esha256:70d9ecd46dbbe10bd0299254a9204b565abb3da8ec861a50856f33201859e75eImage layers
| # debian.sh --arch 'amd64' out/ 'trixie' '@1779062400' |
| ENV PATH=/usr/local/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin |
| ENV LANG=C.UTF-8 |
| RUN /bin/sh -c set -eux; apt-get update; apt-get install -y --no-install-recommends ca-certificates netbase tzdata ; apt-get dist-clean # buildkit |
| ENV GPG_KEY=7169605F62C751356D054A26A821E680E5FA6305 |
| ENV PYTHON_VERSION=3.12.13 |
| ENV PYTHON_SHA256=c08bc65a81971c1dd5783182826503369466c7e67374d1646519adf05207b684 |
| RUN /bin/sh -c set -eux; savedAptMark="$(apt-mark showmanual)"; apt-get update; apt-get install -y --no-install-recommends dpkg-dev gcc gnupg libbluetooth-dev libbz2-dev libc6-dev libdb-dev libffi-dev libgdbm-dev liblzma-dev libncursesw5-dev libreadline-dev libsqlite3-dev libssl-dev make tk-dev uuid-dev wget xz-utils zlib1g-dev ; wget -O python.tar.xz "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz"; echo "$PYTHON_SHA256 *python.tar.xz" | sha256sum -c -; wget -O python.tar.xz.asc "https://www.python.org/ftp/python/${PYTHON_VERSION%%[a-z]*}/Python-$PYTHON_VERSION.tar.xz.asc"; GNUPGHOME="$(mktemp -d)"; export GNUPGHOME; gpg --batch --keyserver hkps://keys.openpgp.org --recv-keys "$GPG_KEY"; gpg --batch --verify python.tar.xz.asc python.tar.xz; gpgconf --kill all; rm -rf "$GNUPGHOME" python.tar.xz.asc; mkdir -p /usr/src/python; tar --extract --directory /usr/src/python --strip-components=1 --file python.tar.xz; rm python.tar.xz; cd /usr/src/python; gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; ./configure --build="$gnuArch" --enable-loadable-sqlite-extensions --enable-optimizations --enable-option-checking=fatal --enable-shared $(test "${gnuArch%%-*}" != 'riscv64' && echo '--with-lto') --with-ensurepip ; nproc="$(nproc)"; EXTRA_CFLAGS="$(dpkg-buildflags --get CFLAGS)"; LDFLAGS="$(dpkg-buildflags --get LDFLAGS)"; LDFLAGS="${LDFLAGS:-} -Wl,--strip-all"; arch="$(dpkg --print-architecture)"; arch="${arch##*-}"; case "$arch" in amd64|arm64) EXTRA_CFLAGS="${EXTRA_CFLAGS:-} -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer"; ;; i386) ;; *) EXTRA_CFLAGS="${EXTRA_CFLAGS:-} -fno-omit-frame-pointer"; ;; esac; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-}" ; rm python; make -j "$nproc" "EXTRA_CFLAGS=${EXTRA_CFLAGS:-}" "LDFLAGS=${LDFLAGS:-} -Wl,-rpath='\$\$ORIGIN/../lib'" python ; make install; cd /; rm -rf /usr/src/python; find /usr/local -depth \( \( -type d -a \( -name test -o -name tests -o -name idle_test \) \) -o \( -type f -a \( -name '*.pyc' -o -name '*.pyo' -o -name 'libpython*.a' \) \) \) -exec rm -rf '{}' + ; ldconfig; apt-mark auto '.*' > /dev/null; apt-mark manual $savedAptMark; find /usr/local -type f -executable -not \( -name '*tkinter*' \) -exec ldd '{}' ';' | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); printf "*%s\n", so }' | sort -u | xargs -rt dpkg-query --search | awk 'sub(":$", "", $1) { print $1 }' | sort -u | xargs -r apt-mark manual ; apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; apt-get dist-clean; export PYTHONDONTWRITEBYTECODE=1; python3 --version; pip3 --version # buildkit |
| RUN /bin/sh -c set -eux; for src in idle3 pip3 pydoc3 python3 python3-config; do dst="$(echo "$src" | tr -d 3)"; [ -s "/usr/local/bin/$src" ]; [ ! -e "/usr/local/bin/$dst" ]; ln -svT "$src" "/usr/local/bin/$dst"; done # buildkit |
| CMD ["python3"] |
| ENV PYTHONUNBUFFERED=1 PYTHONDONTWRITEBYTECODE=1 PIP_DISABLE_PIP_VERSION_CHECK=1 PIP_NO_CACHE_DIR=1 PIP_NO_INPUT=1 RISK_LAYER_EMB_DEVICE=cpu LD_LIBRARY_PATH=/usr/local/lib/python3.12/site-packages/torch/lib XDG_CACHE_HOME=/cache HF_HOME=/cache/huggingface SENTENCE_TRANSFORMERS_HOME=/cache/sentence-transformers |
| WORKDIR /app |
| COPY pyproject.toml README.md LICENSE requirements-runtime-lock.txt requirements-embedding-linux-cpu-py312-lock.txt requirements-quanten-linux-py312-lock.txt requirements-ner-lock.txt ./ # buildkit |
| ARG WITH_EMBEDDING=1 |
| ARG WITH_QUANTEN=1 |
| RUN |2 WITH_EMBEDDING=1 WITH_QUANTEN=1 /bin/sh -c pip install --require-hashes --only-binary=:all: -r requirements-runtime-lock.txt && if [ "$WITH_EMBEDDING" = "1" ]; then pip install --require-hashes --only-binary=:all: -r requirements-embedding-linux-cpu-py312-lock.txt; fi && if [ "$WITH_QUANTEN" = "1" ]; then pip install --require-hashes --only-binary=:all: -r requirements-quanten-linux-py312-lock.txt; fi # buildkit |
| RUN |2 WITH_EMBEDDING=1 WITH_QUANTEN=1 /bin/sh -c pip install --require-hashes --only-binary=:all: -r requirements-ner-lock.txt && pip check # buildkit |
| COPY risk_layer ./risk_layer # buildkit |
| COPY catalog ./catalog # buildkit |
| RUN |2 WITH_EMBEDDING=1 WITH_QUANTEN=1 /bin/sh -c pip install --no-build-isolation --no-deps . # buildkit |
| ARG RISK_LAYER_UID=1000 |
| ARG RISK_LAYER_GID=1000 |
| RUN |4 WITH_EMBEDDING=1 WITH_QUANTEN=1 RISK_LAYER_UID=1000 RISK_LAYER_GID=1000 /bin/sh -c groupadd --gid "$RISK_LAYER_GID" risklayer && useradd --uid "$RISK_LAYER_UID" --gid "$RISK_LAYER_GID" --home-dir /home/risklayer --create-home --shell /usr/sbin/nologin risklayer && install -d -o risklayer -g risklayer -m 0750 /app/corpus /app/definitionen /cache /state/embedding # buildkit |
| VOLUME [/app/corpus] |
| EXPOSE [8000/tcp] |
| USER risklayer:risklayer |
| HEALTHCHECK {Test:[CMD-SHELL python -c "import os,urllib.request,sys; t=os.environ.get('RISK_LAYER_TOKEN',''); h={'Authorization':'Bearer '+t} if t else {}; sys.exit(0 if urllib.request.urlopen(urllib.request.Request('http://127.0.0.1:8000/v1/health',headers=h),timeout=4).status==200 else 1)"] Interval:30s Timeout:5s StartPeriod:20s StartInterval:0s Retries:3} |
| CMD ["python" "-m" "risk_layer.web" "--host" "0.0.0.0" "--port" "8000" "--graph" "corpus/graph.sqlite"] |
| USER root |
| COPY --chown=root:root .managed-release/ /release/ # buildkit |
| ARG ALLOW_MISSING_EMBEDDING_INDEX=0 |
| RUN |1 ALLOW_MISSING_EMBEDDING_INDEX=0 /bin/sh -c test -r /release/festwissen-manifest.json && test -r /release/catalog/begriffe.yaml && test -r /release/corpus/graph.sqlite && test -r /release/models/bge-m3/model-manifest.json && if test "$ALLOW_MISSING_EMBEDDING_INDEX" = 1; then if test -e /release/corpus/embedding/meta.json || test -e /release/corpus/embedding/vectors.npy; then test -r /release/corpus/embedding/meta.json && test -r /release/corpus/embedding/vectors.npy; fi; else test -r /release/corpus/embedding/meta.json && test -r /release/corpus/embedding/vectors.npy; fi && chmod -R u=rwX,go=rX /release # buildkit |
| WORKDIR /release |
| USER risklayer:risklayer |
| CMD ["python" "-m" "risk_layer.web" "--host" "0.0.0.0" "--port" "8000" "--katalog" "/release/catalog/begriffe.yaml" "--berater" "/app/definitionen" "--graph" "/release/corpus/graph.sqlite"] |