# The app: one image, one FastAPI, one bucket, one URL.
#
# NO web stage: this module is an API, and the template's UI build stage was copied in with it
# — referencing a web/package.json that does not exist here, so `docker build` failed on the
# first COPY. The package shipped for weeks in that state because nothing ever built it.
# A front end belongs in a stage like the one in crm-suite-app; do not carry an empty one.
#
# Build context is this directory:
#     docker build -t <customer> .
# Ignite builds it the same way on `git push` (Kaniko, via .dodil/deploy.yaml).

FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt ./
RUN pip install --no-cache-dir -r requirements.txt

# Copy every module with a GLOB, never a hand-maintained list. A list drifts: an app shipped
# one, a module was added without updating it, and the pod crash-looped on ModuleNotFoundError
# *behind a healthy gateway* — the public URL still answered 401, so it looked deployed.
COPY *.py ./
COPY modules/ ./modules/
COPY schema.sql ./

ENV PORT=8080
EXPOSE 8080

# Ignite runs pods with runAsNonRoot, and the kubelet cannot resolve a username against
# /etc/passwd: the image MUST declare a NUMERIC uid, or admission fails with "image will run
# as root" AFTER a successful image pull — which reads like a registry problem and is not.
RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin app \
 && chown -R 10001:10001 /app
USER 10001

CMD ["sh", "-c", "uvicorn main:app --host 0.0.0.0 --port ${PORT:-8080}"]
