# ── Stage 1: deps ───────────────────────────────────────────────────────────── FROM python:3.12-slim AS deps COPY requirements.txt . RUN pip install --no-cache-dir --prefix=/install -r requirements.txt # ── Stage 2: runtime ────────────────────────────────────────────────────────── FROM python:3.12-slim AS runtime RUN useradd --create-home --shell /bin/bash app WORKDIR /home/app COPY --from=deps /install /usr/local COPY app/ ./app/ COPY app.py . # Streamlit writes its own config here — ensure the user owns it RUN mkdir -p /home/app/.streamlit && chown -R app:app /home/app USER app EXPOSE 8501 # --server.headless=true suppresses the "want to contribute?" prompt # --server.address=0.0.0.0 listens on all interfaces (required inside a pod) # --server.fileWatcherType=none disables inotify — not useful in a container CMD ["streamlit", "run", "app.py", "--server.port=8501", "--server.address=0.0.0.0", "--server.headless=true", "--server.fileWatcherType=none"]