Skip to content

SEAB-7766 Build the Docker image on Alpine and drop pip from it - #7

Merged
denis-yuen merged 1 commit into
developfrom
feature/image_reduction
Sep 25, 2026
Merged

denis-yuen merged 1 commit into
developfrom
feature/image_reduction

Conversation

@denis-yuen

@denis-yuen denis-yuen commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Description
Switches both Dockerfile stages from python:3.13-slim-bookworm to python:3.13-alpine3.24, matching the Alpine 3.24 images in dockstore-deploy, and uninstalls pip from the runtime image (its vendored msgpack/setuptools were the only Python CVEs). The image drops from 223 MB to 139 MB (86 → 53 MB compressed), and Trivy goes from 251 unfixable Debian CVEs plus 3 Python ones to none. It still runs as uid 10001 with the same HEALTHCHECK.

Review Instructions
Based on #5, so review only the last commit. docker build . then check that /health responds and the container reports healthy, or rely on the CI smoke test. After the image is published to Quay, MCP_DOCKER_TAG in dockstore-deploy's DockstoreStack.java needs updating.

Issue
https://ucsc-cgl.atlassian.net/browse/SEAB-7766

Security and Privacy

None, should reduce risks due to fewer dependencies in the deployed image

  • Security and Privacy assessed

e.g. Does this change...

  • Any user data we collect, or data location?
  • Access control, authentication or authorization?
  • Encryption features?

Please make sure that you've checked the following before submitting your pull request. Thanks!

  • Check that you pass the basic style checks and unit tests by running make check
  • Ensure that the PR targets the correct branch. Check the milestone or fix version of the ticket.
  • If you are changing dependencies, check the Snyk status check or the dashboard to ensure you are not introducing new high/critical vulnerabilities
  • Assume that arguments passed to a tool can be malicious, and sanitize and/or check for Denial of Service type values, e.g., massive sizes
  • Do not log or return secrets/credentials in a tool's response, error message, or debug output
  • If this PR is for a user-facing feature, create and link a documentation ticket for this feature (usually in the same milestone as the linked issue). Style points if you create a documentation PR directly and link that instead.

🤖 Generated with Claude Code

@denis-yuen denis-yuen self-assigned this Sep 24, 2026
@denis-yuen
denis-yuen marked this pull request as ready for review September 24, 2026 14:22
@denis-yuen

Copy link
Copy Markdown
Member Author
Screenshot from 2026-09-24 10-53-50

Smaller, tested still functional on qa.dockstore.org/mcp

@denis-yuen
denis-yuen requested review from a team and svonworl and removed request for a team September 24, 2026 14:56
@denis-yuen

Copy link
Copy Markdown
Member Author

Or from quay

Screenshot from 2026-09-24 11-48-30

@denis-yuen
denis-yuen added this pull request to stack #8 September 24, 2026 18:06
@denis-yuen
denis-yuen force-pushed the feature/image_reduction branch 2 times, most recently from b6dcf7a to 046c39b Compare September 24, 2026 21:17
@denis-yuen
denis-yuen removed this pull request from stack #8 September 24, 2026 21:20
@denis-yuen
denis-yuen changed the base branch from feature/trs_thin_prototype to feature/trs_initial_hookup September 24, 2026 21:20
@denis-yuen
denis-yuen added this pull request to stack #11 September 24, 2026 21:22
Base automatically changed from feature/trs_initial_hookup to develop September 25, 2026 13:58
Switch both stages from python:3.13-slim-bookworm to python:3.13-alpine3.24,
matching the Alpine 3.24 images in dockstore-deploy, and uninstall pip from
the runtime image. The image shrinks from 223 MB to 139 MB (86 MB to 53 MB
compressed), and Trivy goes from 251 unfixable Debian CVEs plus 3 in pip's
vendored msgpack/setuptools to none.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@denis-yuen
denis-yuen force-pushed the feature/image_reduction branch from 046c39b to bafb4f7 Compare September 25, 2026 13:58
@denis-yuen
denis-yuen merged commit ba2448d into develop Sep 25, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants