FROM ghcr.io/berriai/litellm:main-v1.74.0-stable # LiteLLM's official image runs as root. Cloudron's sandboxing (read-only # rootfs, AppArmor, dropped capabilities) still applies to root inside the # container, so we keep root to match the base image and avoid /app/data # volume-ownership issues. # Create the data directory (Cloudron mounts the localstorage volume here) RUN mkdir -p /app/data /app/code # Create a startup script that configures LiteLLM with Cloudron addons COPY start.sh /app/code/start.sh RUN chmod +x /app/code/start.sh # Default config — will be overridden by Cloudron env vars at runtime COPY config.yaml /app/data/config.yaml # Override the base image's ENTRYPOINT (which is `litellm`) so our # startup script runs instead of being passed as an argument to litellm. ENTRYPOINT ["/app/code/start.sh"] # LiteLLM v1.74.0 hardcodes `origins = ["*"]` (with allow_credentials=True) in # proxy_server.py and ignores LITELLM_CORS_ALLOWED_ORIGINS entirely. Rewrite it # to honour the env var so we can lock CORS to the chat origin. Patch every copy # (site-packages is what the running CLI imports; /app/litellm is a dev copy). RUN sed -i 's/^origins = \["\*"\]$/import os; origins = os.getenv("LITELLM_CORS_ALLOWED_ORIGINS", "*").split(",")/' \ /usr/lib/python3.13/site-packages/litellm/proxy/proxy_server.py \ /app/litellm/proxy/proxy_server.py