# syntax=docker/dockerfile:1

# --- Build stage -------------------------------------------------------------
# Compile a static Go binary. The Vue panel is pre-built into internal/api/dist
# and embedded via //go:embed, so no Node toolchain is needed here.
FROM golang:1.26-alpine3.24 AS build

WORKDIR /src

# Cache module downloads separately from the source for faster rebuilds.
COPY go.mod ./
# go.sum is optional (stdlib-only module today); copy it if present.
COPY go.su[m] ./
RUN go mod download

COPY . .

# CGO_ENABLED=0 produces a static binary that runs on a bare alpine image. The
# entry point is the cmd/server package.
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-s -w" -o /out/api-server ./cmd/server

# --- Runtime stage -----------------------------------------------------------
FROM alpine:3.24

# HTTPS calls to PocketBase need CA certificates; tzdata for correct timestamps.
# su-exec lets the entrypoint fix /data ownership as root and then drop to app.
RUN apk add --no-cache ca-certificates tzdata su-exec

# Run as an unprivileged user.
RUN addgroup -S app && adduser -S -G app app

COPY --from=build /out/api-server /usr/local/bin/api-server

# The server writes two files relative to its working directory: plugins.json
# (plugin enable-state + config) and .env, which the panel rewrites when a
# superadmin retargets the PocketBase connection. Both must therefore live on a
# writable, persistent path — hence /data, owned by the unprivileged user and
# declared as a volume. A fresh named volume inherits this ownership.
RUN mkdir -p /data && chown app:app /data
WORKDIR /data
VOLUME /data

# A fresh named volume inherits /data's ownership, but two common cases do not:
# a host bind mount (API_DATA=/srv/... in docker-compose.prod.yml) arrives owned
# by root, and so does a volume created by an image from before /data existed,
# when the server ran with a root-owned working directory. In both cases the
# unprivileged process cannot write plugins.json — which shows up as plugins
# that enable fine in the panel and come back disabled after the next redeploy.
# So the entrypoint starts as root purely to fix ownership, then drops to app.
RUN cat > /entrypoint.sh <<'ENTRY'
#!/bin/sh
set -e
if [ "$(id -u)" = "0" ]; then
    mkdir -p /data
    if [ "$(stat -c %U /data 2>/dev/null)" != "app" ]; then
        echo "entrypoint: taking ownership of /data"
        chown -R app:app /data
    fi
    exec su-exec app "$@"
fi
# Already unprivileged (docker run --user ...): nothing to drop, just run.
exec "$@"
ENTRY
RUN chmod +x /entrypoint.sh

# Config comes entirely from environment variables (see .env.example).
# POCKETBASE_ADMIN_EMAIL / _PASSWORD are optional at startup: without them the
# server still runs and a superadmin can configure the connection from the panel.
ENV API_ADDR=:8080 \
    PLUGINS_FILE=/data/plugins.json
EXPOSE 8080

# Liveness only: /healthz answers 200 as soon as the process is serving, and
# does not depend on PocketBase, so a database outage does not mark the
# container unhealthy. Lets compose gate dependants on condition: service_healthy.
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
    CMD wget -qO- http://127.0.0.1:8080/healthz >/dev/null 2>&1 || exit 1

# The entrypoint drops to the unprivileged app user after fixing /data.
ENTRYPOINT ["/entrypoint.sh"]
CMD ["/usr/local/bin/api-server"]
