# syntax=docker/dockerfile:1
FROM python:3.14.2-slim

# uv: fast, reproducible dependency installs
COPY --from=ghcr.io/astral-sh/uv:latest /uv /uvx /bin/

ENV PYTHONUNBUFFERED=1 \
    PYTHONDONTWRITEBYTECODE=1 \
    UV_SYSTEM_PYTHON=1 \
    UV_LINK_MODE=copy \
    DATA_DIR=/app/data

WORKDIR /app

# Install deps first for better layer caching
COPY requirements.txt ./
RUN --mount=type=cache,target=/root/.cache/uv \
    uv pip install --system -r requirements.txt

# App code (frontend/ is served by FastAPI at /app; see main.py)
COPY . .

# Runtime data dir (mount a volume here to persist okf.db + generated bundles),
# and drop root for a smaller attack surface.
RUN mkdir -p /app/data \
    && useradd --create-home appuser \
    && chown -R appuser /app
USER appuser

EXPOSE 8000

# Liveness probe hits the FastAPI health endpoint.
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
    CMD python -c "import urllib.request; urllib.request.urlopen('http://localhost:8000/health')" || exit 1

# Bind to 0.0.0.0 so the port is reachable from outside the container
CMD ["uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]
