# syntax=docker/dockerfile:1 # ── Stage 1: Build Python agent deps with uv ─────────────────────────────── FROM ghcr.io/astral-sh/uv:python3.12-bookworm-slim AS build ENV PYTHONUNBUFFERED=1 ENV UV_COMPILE_BYTECODE=1 WORKDIR /app # Install build tools for native extensions (azure-cognitiveservices-speech) RUN apt-get update && apt-get install -y --no-install-recommends \ gcc g++ python3-dev libasound2-dev \ && rm -rf /var/lib/apt/lists/* COPY agent/pyproject.toml ./agent/ RUN cd /app/agent && \ uv venv .venv && \ uv pip install --python .venv/bin/python \ "livekit-agents[mcp]~=1.7" \ "livekit-plugins-azure~=1.7" \ "livekit-plugins-openai~=1.7" \ "python-dotenv" # ── Stage 2: Runtime (use same base for Python compat) ───────────────────── FROM ghcr.io/astral-sh/uv:python3.12-bookworm-slim AS runtime ENV PYTHONUNBUFFERED=1 # Install LiveKit server binary + supervisord + nginx RUN apt-get update && apt-get install -y --no-install-recommends \ curl ca-certificates supervisor nginx libasound2 iproute2 \ && rm -rf /var/lib/apt/lists/* # Download LiveKit server (latest stable) ARG LIVEKIT_VERSION=v1.13.5 ARG LIVEKIT_TAG=1.13.5 RUN curl -sSL "https://github.com/livekit/livekit/releases/download/${LIVEKIT_VERSION}/livekit_${LIVEKIT_TAG}_linux_amd64.tar.gz" \ | tar xz -C /usr/local/bin/ livekit-server \ && chmod +x /usr/local/bin/livekit-server \ && ln -sf /usr/local/bin/livekit-server /usr/local/bin/livekit # Copy Python agent + venv from build stage COPY --from=build /app/agent/.venv /opt/voice-agent/.venv COPY agent/agent.py /opt/voice-agent/agent.py COPY agent/web_mcp.py /opt/voice-agent/web_mcp.py # Copy web frontend + token endpoint COPY web/ /var/www/voice/ COPY web/token_server.py /opt/voice/token_server.py # Config files COPY livekit.yaml /etc/livekit.yaml COPY supervisord.conf /etc/supervisor/conf.d/voice.conf # Configure nginx to serve the voice UI on port 8090 over HTTPS. # Browsers require a secure context (HTTPS or localhost) for microphone access. # The self-signed cert (with the LAN IP in the SAN) is generated at container # start by entrypoint.sh. RUN rm -f /etc/nginx/sites-enabled/default \ && mkdir -p /etc/voice/certs \ && printf 'server {\n listen 8090 ssl;\n root /var/www/voice;\n index index.html;\n ssl_certificate /etc/voice/certs/cert.pem;\n ssl_certificate_key /etc/voice/certs/key.pem;\n location /token {\n proxy_pass http://127.0.0.1:8091/token;\n proxy_set_header Content-Type application/json;\n }\n location = /livekit {\n return 301 /livekit/;\n }\n location /livekit/ {\n proxy_pass http://127.0.0.1:7880/;\n proxy_http_version 1.1;\n proxy_set_header Upgrade $http_upgrade;\n proxy_set_header Connection "upgrade";\n proxy_set_header Host $host;\n proxy_read_timeout 3600s;\n proxy_send_timeout 3600s;\n }\n location / {\n try_files $uri $uri/ =404;\n }\n}\n' \ > /etc/nginx/sites-available/voice \ && ln -sf /etc/nginx/sites-available/voice /etc/nginx/sites-enabled/voice # Create non-root user for agent RUN useradd -m -s /bin/bash voiceuser || true COPY entrypoint.sh /entrypoint.sh RUN chmod +x /entrypoint.sh EXPOSE 7880 7881 7882/udp 8090 ENTRYPOINT ["/entrypoint.sh"] CMD ["supervisord", "-n", "-c", "/etc/supervisor/conf.d/voice.conf"]