# Dockerfile
FROM node:20-alpine

# Install runtime tools needed by features (openssl for /provision-vc CSR generation in vcProvisionService).
# wget is provided by busybox for the HEALTHCHECK.
RUN apk add --no-cache openssl

# Create non-root user for security
RUN addgroup -S appgroup && adduser -S appuser -G appgroup

WORKDIR /app

# Copy package files first for better layer caching
COPY package*.json ./
RUN npm ci --only=production && npm cache clean --force

# Copy the rest of the application
COPY . .

# Create directories for runtime data (logs, storage, config for the mounted tokens file)
RUN mkdir -p logs storage config && chown -R appuser:appgroup /app

# Switch to non-root user
USER appuser

# Expose port
EXPOSE 1800

# Health check (uses wget which is available in alpine)
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
  CMD wget --no-verbose --tries=1 --spider http://localhost:1800/health || exit 1

# Start the app
CMD ["npm", "start"]