# Flask Dockerfile Generator

URL: /dockerizer/flask

Generate a production Dockerfile for a Flask app served by Gunicorn, with dependencies resolved in a separate stage and a non-root runtime.

## Default configuration

- `appName` (App name): flask — Used for the image tag, the compose service and the OCI labels.

- `port` (Port): 8000 — The port the app listens on inside the container. Keep it above 1024 so the process can bind it without root.

- `appModule` (WSGI application): app:app — module:variable — the path to your Flask() instance, as you would pass it to gunicorn.

- `workers` (Worker processes): 3 — A common starting point is (2 × CPU cores) + 1. Keep it low if the container has a small CPU limit.

- `pythonVersion` (Python version): 3.13

- `installer` (Dependency manager): uv — uv resolves and installs an order of magnitude faster than pip and reads the same pyproject.toml.

- `baseVariant` (Base image): slim — Debian slim is the right default for Python — Alpine has no manylinux wheels, so every C extension compiles from source.

- `database` (Database service): none — Adds the database to docker-compose.yml with a healthcheck, a named volume and a DATABASE_URL wired into the app.

- `redis` (Redis service): false — Adds Redis to docker-compose.yml and exposes REDIS_URL to the app.

- `cacheMounts` (BuildKit cache mounts): true — Persists the package manager store between builds. Repeat builds skip the download entirely.

- `multiArch` (Multi-architecture build): false — Adds BUILDPLATFORM/TARGETARCH so `docker buildx build --platform linux/amd64,linux/arm64` cross-compiles natively.

- `healthcheck` (Healthcheck): true — Adds a HEALTHCHECK so orchestrators can restart an unresponsive container.

- `tini` (tini init): false — Runs the app under tini so signals and zombie processes are handled properly.

- `ociLabels` (OCI labels): false — Adds org.opencontainers.image.* metadata to the final image.

- `buildSecret` (Build secret mount): false — Reads a private registry token via --mount=type=secret so it never lands in an image layer.

## Generated files

### Dockerfile

Multi-stage build: dependencies, compilation and the runtime image are separate, so only what the app needs at runtime ships.

```docker
# syntax=docker/dockerfile:1
# Generated by Easypanel Dockerizer — https://easypanel.io/dockerizer

# --- Base ---------------------------------------------
FROM python:3.13-slim AS base

# Unbuffered output so logs reach the daemon immediately
ENV PYTHONUNBUFFERED=1
ENV PYTHONDONTWRITEBYTECODE=1
ENV PIP_DISABLE_PIP_VERSION_CHECK=1
ENV PATH="/app/.venv/bin:$PATH"
WORKDIR /app

# --- Dependencies -------------------------------------
FROM base AS deps

# Toolchain for packages that have no prebuilt wheel
RUN apt-get update \
 && apt-get install -y --no-install-recommends build-essential libpq-dev libjpeg-dev zlib1g-dev \
 && rm -rf /var/lib/apt/lists/*

# uv ships as a static binary — copy it in rather than pip-installing it
COPY --from=ghcr.io/astral-sh/uv:latest /uv /uvx /bin/
ENV UV_COMPILE_BYTECODE=1
ENV UV_LINK_MODE=copy

# Lockfile only, so application edits never re-resolve the tree
COPY pyproject.toml uv.lock* ./
RUN --mount=type=cache,id=uv-cache,target=/root/.cache/uv,sharing=locked \
    uv sync --frozen --no-install-project --no-dev

# --- Runtime ------------------------------------------
FROM base AS runtime

# Shared libraries the compiled wheels link against
RUN apt-get update \
 && apt-get install -y --no-install-recommends libpq5 libjpeg62-turbo \
 && rm -rf /var/lib/apt/lists/*

# Only the resolved virtualenv comes across — no compilers, no headers
COPY --from=deps /app/.venv /app/.venv
RUN groupadd --system --gid 1001 app \
 && useradd --system --uid 1001 --gid app app
COPY --chown=app:app . .
ENV PORT=8000
USER app
EXPOSE 8000
STOPSIGNAL SIGTERM

# Lets Docker, Compose and Easypanel see when the app is wedged
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
  CMD ["python", "-c", "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:8000/').status < 400 else 1)"]
CMD ["gunicorn", "app:app", "--bind", "0.0.0.0:8000", "--workers", "3", "--access-logfile", "-", "--error-logfile", "-"]

```

### .dockerignore

Keeps the build context small and stops secrets and local dependencies from reaching an image layer.

```bash
# Version control
.git
.gitignore
.github

# Secrets — never bake these into an image layer
.env
.env.*
!.env.example
*.pem
*.key

# Editor and OS noise
.vscode
.idea
.DS_Store
Thumbs.db

# Docs and local tooling
README.md
LICENSE
docs
.editorconfig
docker-compose*.yml
Dockerfile*
.dockerignore

# Python build and cache artefacts
__pycache__
**/__pycache__
*.py[cod]
*.egg-info
.venv
venv
env
.pytest_cache
.mypy_cache
.ruff_cache
.tox
htmlcov
.coverage

```

### docker-compose.yml

Runs the image locally with its backing services, wired together and health-gated.

```yaml
services:
  app:
    build:
      context: .
      dockerfile: Dockerfile
    restart: unless-stopped
    ports:
      - "8000:8000"

```

## Frequently asked questions

### Why not just use `flask run`?

The built-in server is a development convenience — single-threaded, no process supervision and not hardened. Flask's own documentation tells you not to deploy it.

### My app factory is create_app(). What do I put in the module field?

`app:create_app()` — Gunicorn will call it. The parentheses are required.

## Related generators

- [FastAPI](/dockerizer/fastapi)

- [Django](/dockerizer/django)

- [Node.js](/dockerizer/nodejs)

- [PHP](/dockerizer/php)