# syntax=docker/dockerfile:1
# Brain of Reese — production image (Podman/Docker compatible).
#
#   Stage 1 (frontend): minify/bundle the local frontend with esbuild.
#                       NO CDN — every asset is built into this image.
#   Stage 2 (python):   install dependencies with uv (locked).
#   Stage 3 (runtime):  slim, non-root, migrations + uvicorn.

# ---------- Stage 1: frontend ----------
FROM docker.io/node:22-alpine AS frontend
WORKDIR /build
# Global install: puts the pinned esbuild binary on the PATH for the build step below
# (a local `npm install` leaves it in node_modules/.bin, invisible to RUN).
RUN npm install --no-audit --no-fund -g esbuild@0.25.5
COPY frontend ./
RUN mkdir -p /out/assets \
    && esbuild ./assets/app.js      --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/app.js \
    && esbuild ./assets/sources.js  --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/sources.js \
    && esbuild ./assets/document.js --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/document.js \
    && esbuild ./assets/login.js    --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/login.js \
    && esbuild ./assets/tuning.js   --bundle --minify --format=esm --target=es2022 --outfile=/out/assets/tuning.js \
    && esbuild ./assets/markdown.js --minify --outfile=/out/assets/markdown.js \
    && esbuild ./assets/styles.css  --minify --outfile=/out/assets/styles.css \
    && cp ./index.html ./sources.html ./document.html ./login.html ./tuning.html /out/

# ---------- Stage 2: python dependencies ----------
FROM docker.io/python:3.12-slim AS python
WORKDIR /app
COPY --from=ghcr.io/astral-sh/uv:latest /uv /usr/local/bin/uv
COPY pyproject.toml uv.lock ./
RUN uv sync --frozen --no-dev --no-cache --no-install-project
COPY app ./app
RUN uv sync --frozen --no-dev --no-cache

# ---------- Stage 3: runtime ----------
FROM docker.io/python:3.12-slim AS runtime
ENV PATH="/app/.venv/bin:$PATH" \
    PYTHONUNBUFFERED=1 \
    PYTHONDONTWRITEBYTECODE=1 \
    BOR_STATIC_DIR=/app/static \
    BOR_ENVIRONMENT=production
RUN useradd --create-home --uid 10001 reese
WORKDIR /app
COPY --from=python /app/.venv /app/.venv
COPY --from=python /app/app /app/app
# app/api/sync.py (phase 32) imports scripts.git_sync / scripts.import_docs
# at module level — the scripts package must ship in the image or the
# container crashes on boot (phase 33: ModuleNotFoundError: No module
# named 'scripts').
COPY scripts ./scripts
COPY --from=frontend /out /app/static
COPY alembic ./alembic
COPY alembic.ini ./alembic.ini
COPY scripts/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh && chown -R reese:reese /app
USER reese
EXPOSE 8000
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=5 \
  CMD ["python", "-c", "import sys, httpx; sys.exit(0 if httpx.get('http://127.0.0.1:8000/api/health', timeout=4).status_code == 200 else 1)"]
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
