FROM ghcr.io/berriai/litellm:main-v1.74.0-stable # Cloudron runs apps as the 'cloudron' user (uid 1000) by default. # LiteLLM's official image runs as root; we switch to cloudron for security. # However, LiteLLM needs to write to /app/data for its database/config. USER root # Install supervisor to manage processes (LiteLLM + optional cron) RUN pip install --no-cache-dir supervisor # Create the data directory and set ownership RUN mkdir -p /app/data && chown -R cloudron:cloudron /app/data # Create a startup script that configures LiteLLM with Cloudron addons COPY start.sh /app/code/start.sh RUN chmod +x /app/code/start.sh && chown cloudron:cloudron /app/code/start.sh # Default config — will be overridden by Cloudron env vars at runtime COPY config.yaml /app/data/config.yaml RUN chown cloudron:cloudron /app/data/config.yaml USER cloudron CMD ["/app/code/start.sh"]