core: add ci
Some checks failed
Build and Publish Docker Images / build-and-push (push) Has been cancelled

This commit is contained in:
2025-09-17 09:59:37 +02:00
parent ad27f1d5e6
commit 5d993e9e14
4 changed files with 150 additions and 0 deletions

17
.env.docker Normal file
View File

@@ -0,0 +1,17 @@
# Configuration pour Docker - COPIEZ CE FICHIER EN .env ET MODIFIEZ
# IMPORTANT: Générez une clé SECRET_KEY unique et sécurisée !
# Clé secrète Flask (OBLIGATOIRE - minimum 32 caractères)
# Générez une nouvelle clé avec: python -c "import secrets; print(secrets.token_hex(32))"
SECRET_KEY=CHANGEZ-MOI-cle-secrete-unique-minimum-32-caracteres-obligatoire-docker
# Base de données (stockée dans le volume ./instance)
DATABASE_URL=sqlite:///instance/school_management.db
# Configuration production
FLASK_ENV=production
DEBUG=false
LOG_LEVEL=INFO
# Configuration optionnelle
WTF_CSRF_TIME_LIMIT=3600

View File

@@ -0,0 +1,59 @@
name: Build and Publish Docker Images
on:
push:
branches:
- main
tags:
- "v*"
workflow_dispatch:
env:
REGISTRY: ${{ secrets.REGISTRY_URL }}
NAMESPACE: ${{ secrets.REGISTRY_NAMESPACE || 'notytex' }}
jobs:
build-and-push:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to Docker Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ secrets.REGISTRY_USERNAME }}
password: ${{ secrets.REGISTRY_PASSWORD }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ secrets.REGISTRY_USERNAME }}/${{ env.NAMESPACE }}
tags: |
type=ref,event=branch,enable={{is_not_default_branch}}
# type=ref,event=pr
type=ref,event=tag
type=raw,value=latest,enable={{is_default_branch}}
# type=sha,prefix={{branch}}-,suffix=-{{date 'YYYYMMDD-HHmmss'}},enable={{is_default_branch}}
labels: |
org.opencontainers.image.source=https://${{ env.REGISTRY }}/${{ secrets.REGISTRY_USERNAME }}/${{ env.NAMESPACE }}
- name: Build and push Docker image
id: build
uses: docker/build-push-action@v5
with:
context: .
dockerfile: Dockerfile
registry: ${{ env.REGISTRY }}
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
platforms: linux/amd64
- name: Image digest
run: echo "Image pushed with digest ${{ steps.build.outputs.digest }}"

39
Dockerfile Normal file
View File

@@ -0,0 +1,39 @@
# Dockerfile pour Notytex - Système de Gestion Scolaire
FROM python:3.11-slim-bookworm
# Variables d'environnement pour uv et Flask
ENV UV_COMPILE_BYTECODE=1
ENV UV_LINK_MODE=copy
ENV PYTHONUNBUFFERED=1
ENV PYTHONDONTWRITEBYTECODE=1
ENV FLASK_APP=app
ENV FLASK_ENV=production
# Installation d'uv depuis l'image officielle
COPY --from=ghcr.io/astral-sh/uv:latest /uv /bin/uv
# Installation des dépendances avec cache mount (avant changement d'utilisateur)
WORKDIR /app
COPY pyproject.toml uv.lock ./
RUN --mount=type=cache,target=/root/.cache/uv \
uv sync --frozen --no-dev
# Création d'un utilisateur non-root
RUN adduser --disabled-password --gecos '' --shell /bin/bash notytex \
&& chown -R notytex:notytex /app
USER notytex
# Définition du répertoire de travail
WORKDIR /app
# Copie du code source
COPY --chown=notytex:notytex . .
# Création des répertoires nécessaires (volumes seront montés)
RUN mkdir -p instance logs
# Exposition du port Flask
EXPOSE 5000
# Démarrage de l'application (stateless)
CMD ["uv", "run", "flask", "--app", "app", "run", "--host=0.0.0.0", "--port=5000"]

35
docker-compose.yml Normal file
View File

@@ -0,0 +1,35 @@
services:
notytex:
build: .
ports:
- "5000:5000"
environment:
- SECRET_KEY=${SECRET_KEY}
- DATABASE_URL=sqlite:///instance/school_management.db
- FLASK_ENV=production
- DEBUG=false
- LOG_LEVEL=INFO
volumes:
- ./instance:/app/instance
- ./logs:/app/logs
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "curl -f http://localhost:5000/ || exit 1"]
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
# Service d'initialisation (à lancer une seule fois)
notytex-init:
build: .
environment:
- SECRET_KEY=${SECRET_KEY}
- DATABASE_URL=sqlite:///instance/school_management.db
- FLASK_ENV=development
volumes:
- ./instance:/app/instance
- ./logs:/app/logs
command: ["uv", "run", "flask", "--app", "app", "init-db"]
profiles:
- init