* build: migrate packaging metadata to uv * ci: move automation and local tooling to uv * docker: migrate image builds and runtime setup to uv * docs: update install and deployment guidance for uv * chore: align auxiliary scripts and tests with uv * test: harden test_litellm isolation * fix: keep release and health check images self-contained * build: pin uv tooling and health check deps * test: isolate bedrock image request formatting from suite state * test: cover sandbox executor requirements flow * ci: fix circleci no-op command steps * ci: fix circleci publish workflow parsing * fix: stabilize remaining uv migration CI checks * ci: increase matrix test timeout headroom * fix: restore published docker and license coverage * fix: restore proxy runtime build parity * fix: restore proxy extras parity and venv migrations * ci: persist uv path across circleci steps * fix: keep psycopg binary in default test env * docker: preserve prisma cache across stages * test: run local proxy checks through uv python * build: restore runtime deps moved into ci * build: refresh uv lock after upstream merge * fix: restore module import in test_check_migration after merge The conflict resolution imported only the function but the test body references check_migration as a module throughout. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: revert dependency promotions, remove nodejs-wheel-binaries, fix Docker layer caching - Move google-generativeai, Pillow, tenacity back to ci group (they are lazily imported and bloat the base SDK install needlessly) - Remove nodejs-wheel-binaries from extra_proxy and proxy-dev (redundant in Docker where system Node.js is already installed via apk) - Remove all nodejs-wheel node replacement and venv npm patching blocks from Dockerfiles since the wheel is no longer installed - Add --no-default-groups to CodSpeed benchmark workflow so the benchmark environment matches the old minimal pip install footprint - Apply standard uv two-phase Docker pattern: copy metadata first, install deps (cached layer), then copy source and install project - Replace CircleCI enterprise no-op with proper uv sync command Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * chore: regenerate uv.lock after removing nodejs-wheel-binaries Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(ci): use cache/restore instead of cache to prevent cache poisoning The old workflow used actions/cache/restore (read-only). The uv migration changed it to actions/cache (read-write), which zizmor flags as a cache poisoning risk. Restore the safer read-only variant. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(ci): disable setup-uv built-in cache to silence cache-poisoning alert The setup-uv action enables caching by default, which zizmor flags as a cache poisoning risk. Disable it since we already use a read-only cache/restore step. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(ci): disable setup-uv cache in publish workflow Silences zizmor cache-poisoning alert. Publishing workflow runs infrequently on protected branches so caching adds no real benefit. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(test): remove duplicate verbose_logger mock in test_check_migration The logger was patched twice — first via mocker.patch() then via mocker.patch.object(autospec=True). The second call fails because autospec cannot inspect an already-mocked attribute. Remove the redundant first patch. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix(ci): free disk space before Docker build in test-server-root-path The Dockerfile.non_root build ran out of disk on the CI runner. Remove Android SDK, .NET, Boost, and GHC toolchains (~12GB) to free space. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
56 lines
1.7 KiB
Docker
56 lines
1.7 KiB
Docker
ARG UV_IMAGE=ghcr.io/astral-sh/uv:0.10.9@sha256:10902f58a1606787602f303954cea099626a4adb02acbac4c69920fe9d278f82
|
|
FROM $UV_IMAGE AS uvbin
|
|
|
|
FROM python:3.13-slim@sha256:739e7213785e88c0f702dcdc12c0973afcbd606dbf021a589cab77d6b00b579d
|
|
|
|
ARG LITELLM_VERSION=1.83.0
|
|
|
|
WORKDIR /app
|
|
|
|
COPY --from=uvbin /uv /usr/local/bin/uv
|
|
COPY --from=uvbin /uvx /usr/local/bin/uvx
|
|
|
|
RUN apt-get update && \
|
|
apt-get install -y --no-install-recommends gcc libffi-dev nodejs npm && \
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
ENV UV_PROJECT_ENVIRONMENT=/app/.venv \
|
|
UV_LINK_MODE=copy \
|
|
PATH="/app/.venv/bin:${PATH}"
|
|
|
|
COPY schema.prisma .
|
|
|
|
# This image is specifically for validating/installing the published PyPI
|
|
# artifact, not the checked-out source tree.
|
|
# Keep the moved proxy-runtime packages explicit until the published PyPI
|
|
# artifact includes that extra; newer releases will simply dedupe these.
|
|
RUN uv venv --python python && \
|
|
uv pip install --python /app/.venv/bin/python \
|
|
"litellm[proxy,proxy-runtime]==${LITELLM_VERSION}" \
|
|
"google-cloud-aiplatform==1.133.0" \
|
|
"google-genai==1.37.0" \
|
|
"anthropic[vertex]==0.84.0" \
|
|
"grpcio==1.78.0" \
|
|
"prometheus-client==0.20.0" \
|
|
"langfuse==2.59.7" \
|
|
"opentelemetry-api==1.28.0" \
|
|
"opentelemetry-sdk==1.28.0" \
|
|
"opentelemetry-exporter-otlp==1.28.0" \
|
|
"ddtrace==2.19.0" \
|
|
"sentry-sdk==2.21.0" \
|
|
"mangum==0.17.0" \
|
|
"azure-ai-contentsafety==1.0.0" \
|
|
"azure-storage-file-datalake==12.20.0" \
|
|
"pypdf==6.7.5" \
|
|
"llm-sandbox==0.3.31" \
|
|
"detect-secrets==1.5.0" \
|
|
"prisma==0.11.0" \
|
|
"openai==2.24.0"
|
|
|
|
RUN prisma generate --schema=./schema.prisma
|
|
|
|
EXPOSE 4000/tcp
|
|
|
|
ENTRYPOINT ["litellm"]
|
|
CMD ["--port", "4000"]
|