FROM ghcr.io/berriai/litellm:main-v1.74.0-stable # LiteLLM's official image runs as root. Cloudron's sandboxing (read-only # rootfs, AppArmor, dropped capabilities) still applies to root inside the # container, so we keep root to match the base image and avoid /app/data # volume-ownership issues. # Create the data directory (Cloudron mounts the localstorage volume here) RUN mkdir -p /app/data # Tinfoil proxy — a verified local proxy that encrypts request/response bodies # with EHBP (HPKE) before forwarding to the Tinfoil enclave. LiteLLM's openai/ # provider sends plaintext, which Tinfoil rejects (426 EHBP_REQUIRED), so the # proxy sits between LiteLLM and the enclave. Statically-linked Go binary, # pinned to a specific release for reproducible builds. Downloaded with Python # (guaranteed present in the Python base image) rather than curl/wget. RUN python3 -c "import urllib.request; urllib.request.urlretrieve('https://github.com/tinfoilsh/tinfoil-proxy/releases/download/v0.2.3/tinfoil-proxy-linux-amd64', '/app/code/tinfoil-proxy')" \ && chmod +x /app/code/tinfoil-proxy # Create a startup script that configures LiteLLM with Cloudron addons COPY start.sh /app/code/start.sh RUN chmod +x /app/code/start.sh # Default config — will be overridden by Cloudron env vars at runtime COPY config.yaml /app/data/config.yaml # Override the base image's ENTRYPOINT (which is `litellm`) so our # startup script runs instead of being passed as an argument to litellm. ENTRYPOINT ["/app/code/start.sh"]