- Docker Images
- Environment Variables
- Build arguments
- Changelog
- Users and permissions
- Crond
- SSHD
- Adding SSH key
- Complete Python stack
- Orchestration Actions
Use image revision tags such as wodby/python:3.14-rN to select a Wodby image revision.
Major and minor tags use the repository release number, starting at r0. Full-version tags such as
wodby/python:3.14.7-r0 start at r0 for each exact upstream version.
Every published versioned revision tag has a matching annotated Git tag pointing to its release commit.
Existing tags remain available after support for their major or minor version ends.
See release tags for available revisions and the image revision policy for upgrade guidance.
Previously published image tags remain available.
About images:
- All images are based on Alpine Linux
- Base image: python
- GitHub actions builds
- Docker Hub
Supported tags and respective Dockerfile links:
3.14,3,latest(Dockerfile)3.13(Dockerfile)3.12(Dockerfile)3.11(Dockerfile)3.10(Dockerfile)3.14-dev,3-dev(Dockerfile)3.13-dev(Dockerfile)3.12-dev(Dockerfile)3.11-dev(Dockerfile)3.10-dev(Dockerfile)3.14-dev-macos,3-dev-macos(Dockerfile)3.13-dev-macos(Dockerfile)3.12-dev-macos(Dockerfile)3.11-dev-macos(Dockerfile)3.10-dev-macos(Dockerfile)
Images with -dev tag have sudo allowed for all commands for wodby user.
Same as -dev but the default user/group wodby has uid/gid 501/20 to match the macOS default user/group ids.
All images built for linux/amd64, -dev-macos images additionally built for linux/arm64
| Variable | Default value |
|---|---|
GIT_USER_EMAIL |
wodby@example.com |
GIT_USER_NAME |
wodby |
GUNICORN_APP |
myapp.wsgi:application |
GUNICORN_BACKLOG |
2048 |
GUNICORN_KEEPALIVE |
2 |
GUNICORN_LOGLEVEL |
info |
GUNICORN_PROC_NAME |
Gunicorn |
GUNICORN_PYTHONPATH |
|
GUNICORN_SPEW |
False |
GUNICORN_TIMEOUT |
30 |
GUNICORN_WORKER_CLASS |
sync |
GUNICORN_WORKER_CONNECTIONS |
1000 |
GUNICORN_WORKERS |
4 |
SSH_DISABLE_STRICT_KEY_CHECKING |
|
SSH_PRIVATE_KEY |
|
SSHD_GATEWAY_PORTS |
no |
SSHD_HOST_KEYS_DIR |
/etc/ssh |
SSHD_LOG_LEVEL |
INFO |
SSHD_PASSWORD_AUTHENTICATION |
no |
SSHD_PERMIT_USER_ENV |
no |
SSHD_USE_DNS |
yes |
| Argument | Default value |
|---|---|
PYTHON_DEV |
|
PYTHON_DEBUG |
|
WODBY_GROUP_ID |
1000 |
WODBY_USER_ID |
1000 |
Change WODBY_USER_ID and WODBY_GROUP_ID mainly for local dev version of images, if it matches with existing system user/group ids the latter will be deleted.
| Tool | all versions |
|---|---|
| UV | latest |
For changes in each image revision, see the release notes.
You can run Crond with this image changing the command to sudo -E crond -f -d 0 and mounting a crontab file to ./crontab:/etc/crontabs/www-data. Example crontab file contents:
# min hour day month weekday command
*/1 * * * * echo "test" > /mnt/files/cron
You can run SSHD with this image by changing the command to sudo /usr/sbin/sshd -De and mounting authorized public keys to /home/wodby/.ssh/authorized_keys
You can add a private SSH key to the container by mounting it to /home/wodby/.ssh/id_rsa
Default container user is wodby:wodby (UID/GID 1000). Gunicorn runs from www-data:www-data user (UID/GID 82) by default. User wodby is a part of www-data group.
Codebase volume $APP_ROOT (/usr/src/app) owned by wodby:wodby. Files volume $FILES_DIR (/mnt/files) owned by www-data:www-data with 775 mode.
-
files_chmod– in case you need write access forwodbyuser to a file/dir generated bywww-dataon this volume runsudo files_chmod [FILEPATH]script (FILEPATH must be under/mnt/files), it will recursively change the mode toug=rwX,o=rX -
files_chown– in case you manually uploaded files underwodbyuser to files volume and want to change the ownership of those files towww-datarunsudo files_chown [FILEPATH]script (FILEPATH must be under/mnt/files), it will recursively change ownership towww-data:www-data
See https://github.com/wodby/docker4python
Usage:
make COMMAND [params ...]
commands:
migrate
check-ready [host max_try wait_seconds delay_seconds]
files-import source
files-link public_dir
Build with the Makefile to use the base image digests in base-images.mk. Local
builds and CI resolve the same version and variant to the same multi-platform
image. A version without a pin fails before the build starts.
When adding a supported base version or variant, add its image index digest to
base-images.mk. For a custom build, override BASE_IMAGE with a complete
repository:tag@sha256:... reference.
Development variants declare com.wodby.workspace.contract=1. Configuration-only
startup (/docker-entrypoint.sh --configure-runtime) does not rewrite developer
SSH/Git settings, initialize shared storage, or run application hooks. Normal
startup retains its existing behavior. WODBY_WORKSPACE=1 selects the workspace
startup command. Login-shell tools remain available when the developer home is mounted.
workspace-python prepare runs uv sync --locked when uv.lock exists, or installs
requirements.txt into a virtual environment. workspace-python start activates it
and runs Gunicorn with its polling reloader against GUNICORN_APP. Override
WORKSPACE_PYTHON_COMMAND for another server; HOST and PORT default to
0.0.0.0 and 8080. Uvicorn commands receive WATCHFILES_FORCE_POLLING=true unless
explicitly configured otherwise. Custom commands must implement their own reload
behavior. Dependency changes require preparation again.
Dependencies/build output use .wodby-workspace/ in the shared checkout, excluded
through .git/info/exclude without editing .gitignore. A tracked directory or
symlink at that reserved path is refused. The runner's private home is not required
by application pods. Package lifecycle scripts remain application-owned and may
modify files; review Git changes after preparation.
CI checks labels for all image variants and runs configuration, developer-state, reserved-path and runtime tests for development variants. Publish a new image revision before enabling this contract in a consuming service.