Prebuilt image (GHCR)¶
Every change to the image is built by GitHub Actions and published to the
GitHub Container Registry as a multi-arch manifest (linux/amd64,
linux/arm64):
ghcr.io/tommasomarchionni/jeff-docker
Package page: github.com/tommasomarchionni/jeff-docker/pkgs/container/jeff-docker.
Tags¶
| Tag | Meaning | Use it for |
|---|---|---|
latest |
Newest build from main or the newest release |
Trying things out |
edge |
Alias of the newest main build |
Following development |
X.Y.Z (e.g. 0.2.0) |
Immutable release | Production |
X.Y / X |
Newest patch of a minor/major line | Automatic patch updates |
sha-<short-sha> |
Exact commit of this repository | Bisecting, reproducibility |
Using it¶
curl -LO https://raw.githubusercontent.com/tommasomarchionni/jeff-docker/main/docker-compose.prebuilt.yml
curl -L -o .env https://raw.githubusercontent.com/tommasomarchionni/jeff-docker/main/.env.example
# set JEFF_API_KEYS in .env
docker compose -f docker-compose.prebuilt.yml up -d
See Plain Docker.
See Dokploy, Mode A.
Pinning a version¶
Set the tag in .env (or in Dokploy → Environment):
JEFF_DOCKER_TAG=0.2.0
For bit-for-bit reproducibility pin the digest instead of the tag:
image: ghcr.io/tommasomarchionni/jeff-docker@sha256:<digest>
The digest of each release is printed in the GitHub Release notes.
What is inside¶
| Component | Details |
|---|---|
| Base | python:3.12-slim (Debian) |
| PyTorch | CPU-only wheels from download.pytorch.org/whl/cpu |
| Jeff | Upstream main at build time (short SHA in logs and /app/.jeff-revision) |
| Extras | onnx (ONNX Runtime) so the ONNX backend works without rebuilding |
| User | jeff (UID/GID 10001), non-root |
| PID 1 | tini (signal forwarding, zombie reaping) |
| Volumes | /models (weights, ONNX), /data (HF cache) |
| Port | 8000 |
| Health | HEALTHCHECK on /healthz every 30 s, 300 s start period |
The model is not baked into the image: it is downloaded on first start
into the /models volume (see Models).
Verifying the image (supply chain)¶
Each image is published with an SBOM, SLSA provenance and a GitHub artifact attestation:
gh attestation verify oci://ghcr.io/tommasomarchionni/jeff-docker:latest \
-R tommasomarchionni/jeff-docker
docker buildx imagetools inspect ghcr.io/tommasomarchionni/jeff-docker:latest \
--format '{{ json .SBOM }}' | head
Building your own instead¶
Clone the repository and use docker-compose.yml (builds locally), see
Docker Compose. Useful build
arguments:
| Build arg | Default | Purpose |
|---|---|---|
JEFF_REF |
main |
Upstream Jeff branch, tag or commit |
TORCH_VERSION |
2.14.0 |
Must match upstream uv.lock |
TORCH_INDEX_URL |
https://download.pytorch.org/whl/cpu |
.../cu130 (NVIDIA), .../rocm7.2 (AMD) |
UV_EXTRAS |
onnx |
Upstream optional extras |
PYTHON_VERSION |
3.12 |
Upstream requires 3.12 |