From bc033c2417f8656796592837e0eeeeba881a6970 Mon Sep 17 00:00:00 2001 From: Mikita Sirosh Date: Tue, 5 Aug 2025 11:50:20 +0200 Subject: [PATCH 1/5] Optimize Docker setup - Add `.dockerignore` to exclude unnecessary files - Enable forced Python bytecode compilation for faster startup - Use `uv sync --frozen` for strict dependency matching --- .dockerignore | 232 ++++++++++++++++++++++++++++++++++++++++++++++++++ Dockerfile | 29 ++++--- 2 files changed, 248 insertions(+), 13 deletions(-) create mode 100644 .dockerignore diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000..8f07ffd --- /dev/null +++ b/.dockerignore @@ -0,0 +1,232 @@ +# Python-generated files +__pycache__/ +*.py[oc] +build/ +dist/ +wheels/ +*.egg-info + +# Virtual environments +.venv +# Byte-compiled / optimized / DLL files +__pycache__/ +*.py[codz] +*$py.class + +# C extensions +*.so + +# Distribution / packaging +.Python +build/ +develop-eggs/ +dist/ +downloads/ +eggs/ +.eggs/ +lib/ +lib64/ +parts/ +sdist/ +var/ +wheels/ +share/python-wheels/ +*.egg-info/ +.installed.cfg +*.egg +MANIFEST + +# PyInstaller +# Usually these files are written by a python script from a template +# before PyInstaller builds the exe, so as to inject date/other infos into it. +*.manifest +*.spec + +# Installer logs +pip-log.txt +pip-delete-this-directory.txt + +# Unit test / coverage reports +htmlcov/ +.tox/ +.nox/ +.coverage +.coverage.* +.cache +nosetests.xml +coverage.xml +*.cover +*.py.cover +.hypothesis/ +.pytest_cache/ +cover/ + +# Translations +*.mo +*.pot + +# Django stuff: +*.log +local_settings.py +db.sqlite3 +db.sqlite3-journal + +# Flask stuff: +instance/ +.webassets-cache + +# Scrapy stuff: +.scrapy + +# Sphinx documentation +docs/_build/ + +# PyBuilder +.pybuilder/ +target/ + +# Jupyter Notebook +.ipynb_checkpoints + +# IPython +profile_default/ +ipython_config.py + +# pyenv +# For a library or package, you might want to ignore these files since the code is +# intended to run in multiple environments; otherwise, check them in: +# .python-version + +# pipenv +# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control. +# However, in case of collaboration, if having platform-specific dependencies or dependencies +# having no cross-platform support, pipenv may install dependencies that don't work, or not +# install all needed dependencies. +#Pipfile.lock + +# UV +# Similar to Pipfile.lock, it is generally recommended to include uv.lock in version control. +# This is especially recommended for binary packages to ensure reproducibility, and is more +# commonly ignored for libraries. +#uv.lock + +# poetry +# Similar to Pipfile.lock, it is generally recommended to include poetry.lock in version control. +# This is especially recommended for binary packages to ensure reproducibility, and is more +# commonly ignored for libraries. +# https://python-poetry.org/docs/basic-usage/#commit-your-poetrylock-file-to-version-control +#poetry.lock +#poetry.toml + +# pdm +# Similar to Pipfile.lock, it is generally recommended to include pdm.lock in version control. +# pdm recommends including project-wide configuration in pdm.toml, but excluding .pdm-python. +# https://pdm-project.org/en/latest/usage/project/#working-with-version-control +#pdm.lock +#pdm.toml +.pdm-python +.pdm-build/ + +# pixi +# Similar to Pipfile.lock, it is generally recommended to include pixi.lock in version control. +#pixi.lock +# Pixi creates a virtual environment in the .pixi directory, just like venv module creates one +# in the .venv directory. It is recommended not to include this directory in version control. +.pixi + +# PEP 582; used by e.g. github.com/David-OConnor/pyflow and github.com/pdm-project/pdm +__pypackages__/ + +# Celery stuff +celerybeat-schedule +celerybeat.pid + +# SageMath parsed files +*.sage.py + +# Environments +.env +.envrc +.venv +env/ +venv/ +ENV/ +env.bak/ +venv.bak/ + +# Spyder project settings +.spyderproject +.spyproject + +# Rope project settings +.ropeproject + +# mkdocs documentation +/site + +# mypy +.mypy_cache/ +.dmypy.json +dmypy.json + +# Pyre type checker +.pyre/ + +# pytype static type analyzer +.pytype/ + +# Cython debug symbols +cython_debug/ + +# PyCharm +# JetBrains specific template is maintained in a separate JetBrains.gitignore that can +# be found at https://github.com/github/gitignore/blob/main/Global/JetBrains.gitignore +# and can be added to the global gitignore or merged into this file. For a more nuclear +# option (not recommended) you can uncomment the following to ignore the entire idea folder. +#.idea/ + +# Abstra +# Abstra is an AI-powered process automation framework. +# Ignore directories containing user credentials, local state, and settings. +# Learn more at https://abstra.io/docs +.abstra/ + +# Visual Studio Code +# Visual Studio Code specific template is maintained in a separate VisualStudioCode.gitignore +# that can be found at https://github.com/github/gitignore/blob/main/Global/VisualStudioCode.gitignore +# and can be added to the global gitignore or merged into this file. However, if you prefer, +# you could uncomment the following to ignore the entire vscode folder +# .vscode/ + +# Ruff stuff: +.ruff_cache/ + +# PyPI configuration file +.pypirc + +# Marimo +marimo/_static/ +marimo/_lsp/ +__marimo__/ + +# Streamlit +.streamlit/secrets.toml + +# Anecdotes +anecdotes.txt + +# Git +.git +.gitignore +.gitattributes + +# Docker +docker-compose.yml +Dockerfile +.docker +.dockerignore + +# GitHub +.github/ +README.md +LICENSE diff --git a/Dockerfile b/Dockerfile index 1c68090..9c025d5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,19 +1,22 @@ -FROM python:3.13-slim-bookworm +# Use slim image for smaller size +FROM python:3.13-slim -RUN apt-get update && apt-get install -y --no-install-recommends - -WORKDIR /app - -# Install uv +# Install uv package manager COPY --from=ghcr.io/astral-sh/uv:latest /uv /uvx /bin/ -COPY pyproject.toml uv.lock ./ +# Compile Python bytecode for faster startup +ENV UV_COMPILE_BYTECODE=1 + +# Set up application directory +WORKDIR /app -# Install dependencies -RUN uv sync --all-extras --no-dev +# Install Python dependencies using cached mounts for speed +RUN --mount=type=bind,source=uv.lock,target=uv.lock \ + --mount=type=bind,source=pyproject.toml,target=pyproject.toml \ + uv sync --frozen --no-default-groups -COPY main.py ./ -COPY src/ src/ -COPY locales/ locales/ +# Copy all application files +ADD . . -CMD ["uv", "run", "--no-project", "main.py"] +# Start the bot +CMD ["uv", "run", "--no-sync", "main.py"] From 42d27171a0a530fb3bdce775f18da2d6b8a6def6 Mon Sep 17 00:00:00 2001 From: Mikita Sirosh Date: Tue, 5 Aug 2025 11:54:37 +0200 Subject: [PATCH 2/5] Implement caching across build pipeline - Cache UV pip dependencies in Docker builds - Enable Docker layer caching in CI - Cache MyPy between CI runs --- .github/workflows/docker-ci.yml | 2 ++ .github/workflows/python-ci.yml | 12 +++++++++++- Dockerfile | 3 ++- 3 files changed, 15 insertions(+), 2 deletions(-) diff --git a/.github/workflows/docker-ci.yml b/.github/workflows/docker-ci.yml index 871cbf8..0d864f6 100644 --- a/.github/workflows/docker-ci.yml +++ b/.github/workflows/docker-ci.yml @@ -40,3 +40,5 @@ jobs: annotations: ${{ steps.meta.outputs.annotations }} provenance: true sbom: true + cache-from: type=gha + cache-to: type=gha,mode=max diff --git a/.github/workflows/python-ci.yml b/.github/workflows/python-ci.yml index 124bf6a..b4c29ea 100644 --- a/.github/workflows/python-ci.yml +++ b/.github/workflows/python-ci.yml @@ -7,11 +7,13 @@ on: paths: - ".github/workflows/python-ci.yml" - "pyproject.toml" + - "uv.lock" - "**/*.py" pull_request: paths: - ".github/workflows/python-ci.yml" - "pyproject.toml" + - "uv.lock" - "**/*.py" jobs: @@ -31,7 +33,15 @@ jobs: python-version-file: pyproject.toml - name: "Install dependencies" - run: uv sync + run: uv sync --locked + + - name: "Cache MyPy" + uses: actions/cache@v4 + with: + path: .mypy_cache + key: mypy-${{ runner.os }}-${{ hashFiles('uv.lock') }} + restore-keys: | + mypy-${{ runner.os }}- - name: "MyPy: Typecheck" run: uv run mypy . diff --git a/Dockerfile b/Dockerfile index 9c025d5..703c446 100644 --- a/Dockerfile +++ b/Dockerfile @@ -11,7 +11,8 @@ ENV UV_COMPILE_BYTECODE=1 WORKDIR /app # Install Python dependencies using cached mounts for speed -RUN --mount=type=bind,source=uv.lock,target=uv.lock \ +RUN --mount=type=cache,target=/root/.cache/uv \ + --mount=type=bind,source=uv.lock,target=uv.lock \ --mount=type=bind,source=pyproject.toml,target=pyproject.toml \ uv sync --frozen --no-default-groups From 772c6be00d827ef76d1b5cb566861816ddf5684b Mon Sep 17 00:00:00 2001 From: Mikita Sirosh Date: Tue, 5 Aug 2025 11:55:25 +0200 Subject: [PATCH 3/5] Push only the `latest` tag to Docker Hub --- .github/workflows/docker-ci.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/docker-ci.yml b/.github/workflows/docker-ci.yml index 0d864f6..f5384d5 100644 --- a/.github/workflows/docker-ci.yml +++ b/.github/workflows/docker-ci.yml @@ -20,7 +20,6 @@ jobs: with: images: ${{ secrets.DOCKER_USERNAME }}/${{ github.event.repository.name }} tags: | - type=sha,prefix= type=raw,value=latest - name: "Log in to Docker Hub" From e6257ccfa8321617fc75e3e7fcba4d71371d1a6c Mon Sep 17 00:00:00 2001 From: Mikita Sirosh Date: Tue, 5 Aug 2025 11:58:18 +0200 Subject: [PATCH 4/5] Run actions only for PRs to `main` --- .github/workflows/docker-ci.yml | 2 ++ .github/workflows/python-ci.yml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/.github/workflows/docker-ci.yml b/.github/workflows/docker-ci.yml index f5384d5..6f5ce12 100644 --- a/.github/workflows/docker-ci.yml +++ b/.github/workflows/docker-ci.yml @@ -5,6 +5,8 @@ on: branches: - main pull_request: + branches: + - main jobs: build: diff --git a/.github/workflows/python-ci.yml b/.github/workflows/python-ci.yml index b4c29ea..d6fd96a 100644 --- a/.github/workflows/python-ci.yml +++ b/.github/workflows/python-ci.yml @@ -10,6 +10,8 @@ on: - "uv.lock" - "**/*.py" pull_request: + branches: + - main paths: - ".github/workflows/python-ci.yml" - "pyproject.toml" From cffeef7628e084fe04c7249d59e82b78a1b64e4e Mon Sep 17 00:00:00 2001 From: Mikita Sirosh Date: Tue, 5 Aug 2025 12:06:54 +0200 Subject: [PATCH 5/5] Make Docker build dependent on Python checks --- .../workflows/{docker-ci.yml => ci-cd.yml} | 42 +++++++++++++- .github/workflows/python-ci.yml | 55 ------------------- 2 files changed, 39 insertions(+), 58 deletions(-) rename .github/workflows/{docker-ci.yml => ci-cd.yml} (54%) delete mode 100644 .github/workflows/python-ci.yml diff --git a/.github/workflows/docker-ci.yml b/.github/workflows/ci-cd.yml similarity index 54% rename from .github/workflows/docker-ci.yml rename to .github/workflows/ci-cd.yml index 6f5ce12..a882294 100644 --- a/.github/workflows/docker-ci.yml +++ b/.github/workflows/ci-cd.yml @@ -1,4 +1,4 @@ -name: "Docker CI" +name: "CI/CD" on: push: @@ -9,9 +9,45 @@ on: - main jobs: - build: - name: "Build & Push Docker Image" + python: + name: "Python: Lint & Typecheck" runs-on: ubuntu-latest + steps: + - name: "Checkout" + uses: actions/checkout@v4 + + - name: "Install uv" + uses: astral-sh/setup-uv@v5 + + - name: "Set up Python" + uses: actions/setup-python@v5 + with: + python-version-file: pyproject.toml + + - name: "Install dependencies" + run: uv sync --locked + + - name: "Cache MyPy" + uses: actions/cache@v4 + with: + path: .mypy_cache + key: mypy-${{ runner.os }}-${{ hashFiles('uv.lock') }} + restore-keys: | + mypy-${{ runner.os }}- + + - name: "MyPy: Typecheck" + run: uv run mypy . + + - name: "Ruff: Static Analysis" + run: uv run ruff check . + + - name: "Ruff: Format Check" + run: uv run ruff format --check . + + docker: + name: "Docker: Build & Push Image" + runs-on: ubuntu-latest + needs: python steps: - name: "Checkout" uses: actions/checkout@v4 diff --git a/.github/workflows/python-ci.yml b/.github/workflows/python-ci.yml deleted file mode 100644 index d6fd96a..0000000 --- a/.github/workflows/python-ci.yml +++ /dev/null @@ -1,55 +0,0 @@ -name: "Python CI" - -on: - push: - branches: - - main - paths: - - ".github/workflows/python-ci.yml" - - "pyproject.toml" - - "uv.lock" - - "**/*.py" - pull_request: - branches: - - main - paths: - - ".github/workflows/python-ci.yml" - - "pyproject.toml" - - "uv.lock" - - "**/*.py" - -jobs: - lint: - name: "Lint & Typecheck" - runs-on: ubuntu-latest - steps: - - name: "Checkout" - uses: actions/checkout@v4 - - - name: "Install uv" - uses: astral-sh/setup-uv@v5 - - - name: "Set up Python" - uses: actions/setup-python@v5 - with: - python-version-file: pyproject.toml - - - name: "Install dependencies" - run: uv sync --locked - - - name: "Cache MyPy" - uses: actions/cache@v4 - with: - path: .mypy_cache - key: mypy-${{ runner.os }}-${{ hashFiles('uv.lock') }} - restore-keys: | - mypy-${{ runner.os }}- - - - name: "MyPy: Typecheck" - run: uv run mypy . - - - name: "Ruff: Static Analysis" - run: uv run ruff check . - - - name: "Ruff: Format Check" - run: uv run ruff format --check .