# syntax=docker/dockerfile:1
# Multi-stage production build for pyfconfig on the kaya framework.
# Base: alpine:3.24 (python3 = 3.14). Deps come from the kaya Gitea registry
# (primary) with PyPI as fallback. granian ships musllinux wheels, so no
# compiler is strictly required; build-base + python3-dev are kept in the
# builder only as a safety net and are discarded in the runtime image.
#
# apk and pip both use BuildKit cache mounts (type=cache): the package
# caches persist in the builder's cache across builds instead of being
# re-downloaded, and never land in the image layers. Requires BuildKit
# (default for `docker build` / `docker buildx` on modern daemons).

# --- Builder ---------------------------------------------------------------
FROM alpine:3.24 AS builder

RUN --mount=type=cache,target=/var/cache/apk \
    apk add python3 py3-pip build-base python3-dev

WORKDIR /build

COPY pyproject.toml README.md requirements.txt ./
COPY src/ ./src/

RUN --mount=type=cache,target=/root/.cache/pip \
    python3 -m venv /opt/venv \
 && /opt/venv/bin/pip install --upgrade pip \
 && /opt/venv/bin/pip install -r requirements.txt .

# --- Runtime ---------------------------------------------------------------
FROM alpine:3.24

RUN --mount=type=cache,target=/var/cache/apk \
    apk add python3 ca-certificates tzdata \
 && addgroup -S app && adduser -S -G app app

COPY --from=builder /opt/venv /opt/venv

ENV PATH="/opt/venv/bin:$PATH" \
    PYTHONUNBUFFERED=1 \
    PYTHONDONTWRITEBYTECODE=1 \
    GRANIAN_HOST=0.0.0.0 \
    GRANIAN_PORT=8080 \
    GRANIAN_INTERFACE=rsgi

USER app

EXPOSE 8080

HEALTHCHECK --interval=30s --timeout=3s --start-period=10s \
  CMD wget -q -O- http://127.0.0.1:8080/api/health || exit 1

CMD ["granian", "pyfconfig.app:app"]
