mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-01 02:02:20 +00:00
Two upstream "use latest" channels recently drifted past what the
project supports and broke `docker build` for the three legacy
Dockerfiles (Dockerfile, docker/Dockerfile.database,
docker/Dockerfile.non_root):
1. Wolfi's `python3` apk meta-package now resolves to CPython
3.14.x, but `pyproject.toml` pins `requires-python = ">=3.10,
<3.14"`. `uv sync ... --python python3` therefore fails with
"interpreter resolved to Python 3.14.x, which is incompatible
with the project's Python requirement".
2. prisma-python's nodeenv now downloads Node 26.2.0, which on
arm64 is dynamically linked against `libatomic.so.1` — a library
wolfi-base doesn't ship. `prisma generate` then fails with
"node: error while loading shared libraries: libatomic.so.1".
Replace both implicit-latest assumptions with explicit pins in all
three Dockerfiles:
* `apk add python-3.13 python-3.13-dev` instead of the meta
`python3` / `python3-dev` (concrete versioned wolfi packages).
* `uv sync ... --python python3.13` (match the apk binary).
* `ENV UV_PYTHON_DOWNLOADS=0` so uv refuses to silently substitute
a managed CPython if the system interpreter ever goes missing.
* `ENV PRISMA_USE_GLOBAL_NODE=true` so `prisma generate` uses the
apk-installed nodejs instead of nodeenv's "latest" Node.
This matches the pattern the newer componentized Dockerfiles
(backend/, gateway/, migrations/) already use. 3.13 is also the
version `docker/tests/nonroot.yaml` already asserts at
`/usr/local/lib/python3.13/site-packages/prisma/`.
108 lines
3.8 KiB
Text
108 lines
3.8 KiB
Text
# Base image for building
|
|
ARG LITELLM_BUILD_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:3258be472764337fd13095bcbb3182da170243b5819fd67ad4c0754590588b31
|
|
|
|
# Runtime image
|
|
ARG LITELLM_RUNTIME_IMAGE=cgr.dev/chainguard/wolfi-base@sha256:3258be472764337fd13095bcbb3182da170243b5819fd67ad4c0754590588b31
|
|
ARG UV_IMAGE=ghcr.io/astral-sh/uv:0.11.7@sha256:240fb85ab0f263ef12f492d8476aa3a2e4e1e333f7d67fbdd923d00a506a516a
|
|
|
|
FROM $UV_IMAGE AS uvbin
|
|
|
|
FROM $LITELLM_BUILD_IMAGE AS builder
|
|
|
|
WORKDIR /app
|
|
USER root
|
|
|
|
COPY --from=uvbin /uv /usr/local/bin/uv
|
|
COPY --from=uvbin /uvx /usr/local/bin/uvx
|
|
|
|
RUN apk add --no-cache \
|
|
bash \
|
|
gcc \
|
|
python-3.13 \
|
|
python-3.13-dev \
|
|
openssl \
|
|
openssl-dev \
|
|
nodejs \
|
|
npm \
|
|
libsndfile
|
|
|
|
ENV UV_PROJECT_ENVIRONMENT=/app/.venv \
|
|
UV_LINK_MODE=copy \
|
|
UV_PYTHON_DOWNLOADS=0 \
|
|
PRISMA_USE_GLOBAL_NODE=true \
|
|
PATH="/app/.venv/bin:${PATH}"
|
|
|
|
# Copy dependency metadata first for layer caching
|
|
COPY pyproject.toml uv.lock ./
|
|
COPY enterprise/pyproject.toml enterprise/
|
|
COPY litellm-proxy-extras/pyproject.toml litellm-proxy-extras/
|
|
|
|
# Install third-party dependencies (cached unless pyproject.toml/uv.lock change)
|
|
RUN uv sync --frozen --no-install-project --no-install-workspace --no-default-groups --no-editable \
|
|
--extra proxy \
|
|
--extra proxy-runtime \
|
|
--extra extra_proxy \
|
|
--extra semantic-router \
|
|
--python python3.13
|
|
|
|
# Copy full source tree
|
|
COPY . .
|
|
|
|
# Build Admin UI before final sync
|
|
RUN sed -i 's/\r$//' docker/build_admin_ui.sh && chmod +x docker/build_admin_ui.sh && ./docker/build_admin_ui.sh
|
|
|
|
# Install project and workspace packages (fast - deps already cached)
|
|
RUN uv sync --frozen --no-default-groups --no-editable \
|
|
--extra proxy \
|
|
--extra proxy-runtime \
|
|
--extra extra_proxy \
|
|
--extra semantic-router \
|
|
--python python3.13
|
|
|
|
RUN prisma generate --schema=./schema.prisma
|
|
|
|
RUN sed -i 's/\r$//' docker/entrypoint.sh && chmod +x docker/entrypoint.sh && \
|
|
sed -i 's/\r$//' docker/prod_entrypoint.sh && chmod +x docker/prod_entrypoint.sh
|
|
|
|
FROM $LITELLM_RUNTIME_IMAGE AS runtime
|
|
|
|
USER root
|
|
|
|
RUN apk add --no-cache bash openssl tzdata nodejs npm python-3.13 libsndfile && \
|
|
npm install -g npm@11.12.1 tar@7.5.11 glob@11.1.0 @isaacs/brace-expansion@5.0.1 minimatch@10.2.4 diff@8.0.3 && \
|
|
GLOBAL="$(npm root -g)" && \
|
|
find "$GLOBAL/npm" -type d -name "tar" -path "*/node_modules/tar" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/tar" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "glob" -path "*/node_modules/glob" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/glob" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "brace-expansion" -path "*/node_modules/@isaacs/brace-expansion" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/@isaacs/brace-expansion" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "minimatch" -path "*/node_modules/minimatch" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/minimatch" "$d"; \
|
|
done && \
|
|
find "$GLOBAL/npm" -type d -name "diff" -path "*/node_modules/diff" | while read d; do \
|
|
rm -rf "$d" && cp -rL "$GLOBAL/diff" "$d"; \
|
|
done && \
|
|
npm cache clean --force && \
|
|
{ apk del --no-cache npm 2>/dev/null || true; }
|
|
|
|
WORKDIR /app
|
|
ENV PATH="/app/.venv/bin:${PATH}"
|
|
|
|
COPY --from=builder /app /app
|
|
# Prisma binaries live in $HOME/.cache (default prisma-python location),
|
|
# which is /root/.cache here. Copy them from the builder so they survive
|
|
# deployments that volume-mount /app/.cache (e.g. readOnlyRootFilesystem
|
|
# + emptyDir) — otherwise the mount would shadow the baked-in query engine.
|
|
COPY --from=builder /root/.cache /root/.cache
|
|
|
|
RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \
|
|
find /app/.venv -type d -path "*/tornado/test" -delete
|
|
|
|
EXPOSE 4000/tcp
|
|
|
|
ENTRYPOINT ["docker/prod_entrypoint.sh"]
|
|
CMD ["--port", "4000"]
|