# ── Stage 1: dependency builder ───────────────────────────────────────────────
FROM python:3.12-slim AS builder

WORKDIR /build

# Install build deps only — not carried into runtime image
RUN apt-get update \
    && apt-get install -y --no-install-recommends gcc libpq-dev \
    && rm -rf /var/lib/apt/lists/*

COPY requirements.txt .
RUN pip install --no-cache-dir --prefix=/install -r requirements.txt


# ── Stage 2: development ──────────────────────────────────────────────────────
FROM python:3.12-slim AS development

ENV PYTHONDONTWRITEBYTECODE=1 \
    PYTHONUNBUFFERED=1 \
    PYTHONPATH=/app

WORKDIR /app

# Install runtime system deps only
RUN apt-get update \
    && apt-get install -y --no-install-recommends curl libpq5 \
    && rm -rf /var/lib/apt/lists/*

# Non-root user — never run as root
RUN groupadd --gid 1001 ams && useradd --uid 1001 --gid ams --no-create-home ams

# Copy installed packages from builder
COPY --from=builder /install /usr/local

# Keys dir placeholder (mounted at runtime — never baked in)
RUN mkdir -p /app/keys && chown ams:ams /app/keys

USER ams

EXPOSE 8000

# dev: hot reload via volume mount
CMD ["uvicorn", "ams.main:app", "--host", "0.0.0.0", "--port", "8000", "--reload"]


# ── Stage 3: production ───────────────────────────────────────────────────────
FROM python:3.12-slim AS production

ENV PYTHONDONTWRITEBYTECODE=1 \
    PYTHONUNBUFFERED=1 \
    PYTHONPATH=/app

WORKDIR /app

RUN apt-get update \
    && apt-get install -y --no-install-recommends curl libpq5 \
    && rm -rf /var/lib/apt/lists/*

RUN groupadd --gid 1001 ams && useradd --uid 1001 --gid ams --no-create-home ams

COPY --from=builder /install /usr/local

# Copy application code (no tests, no keys)
COPY --chown=ams:ams ams/ ./ams/
COPY --chown=ams:ams alembic/ ./alembic/
COPY --chown=ams:ams alembic.ini .
COPY --chown=ams:ams seed.py .
# The vertical seeder and its role data. Without these the production image can
# run migrations but cannot create a single role or user, so a fresh deployment
# comes up with nobody able to log in — and nothing in the startup path says so.
COPY --chown=ams:ams seed_documented_personas.py .
COPY --chown=ams:ams private/ ./private/
COPY --chown=ams:ams government/ ./government/
# Label printers (seed_printers.py reads printer/*.json). Without these the
# seeder is missing from the image and the deploy step fails on "no such file"
# — the same way the persona seeder did before it was copied in.
COPY --chown=ams:ams seed_printers.py .
COPY --chown=ams:ams printer/ ./printer/

RUN mkdir -p /app/keys && chown ams:ams /app/keys

USER ams

EXPOSE 8000

# /api/v1/health, not /health: the health router is mounted under the /api/v1
# prefix (ams/main.py), so the bare path 404s and every container built from
# this image reported itself unhealthy while serving traffic perfectly well.
#
# Applies to the API only. The worker runs `python -m ams.workers.main` and
# binds no port at all, so compose disables this check for it rather than
# inheriting one it can never satisfy.
HEALTHCHECK --interval=30s --timeout=10s --start-period=15s --retries=3 \
    CMD curl -f http://localhost:8000/api/v1/health || exit 1

# production: no --reload; workers = CPU count
CMD ["uvicorn", "ams.main:app", "--host", "0.0.0.0", "--port", "8000", \
     "--workers", "2", "--no-access-log"]
