# syntax=docker/dockerfile:1.6
#
# DECT relay agent — production image.
#
# BUILD CONTEXT: the REPO ROOT (not this folder). The agent imports
# `../integrations/cisco-dect/*` and `../utils/httpDigestAuth.js`, so
# we mirror the repo's layout under /workspace/ inside the image and
# the relative paths just work.
#
# BUILD FROM REPO ROOT:
#   docker build \
#     --platform=linux/amd64 \
#     -f dect-relay-agent/Dockerfile \
#     -t collabsupport/dect-relay-agent:0.1.0 \
#     .
#
# Or use bundle.sh which wraps this + `docker save` + zip.
#
# WHY NO `apk add`: corporate DCs commonly TLS-intercept HTTPS. Alpine's
# apk fetch of dl-cdn.alpinelinux.org fails inside the container when
# the CA chain includes a proxy cert the container doesn't trust. We
# avoid the problem entirely by not fetching anything from Alpine at
# build time. Signal handling (SIGTERM / SIGINT / SIGUSR2) is done in
# index.js so we don't need tini/dumb-init.
#
# WHY NO RUNTIME `npm install`: the bundle.sh workflow builds this
# image ONCE outside the DC (where npm registry access works), saves
# it as a tarball, and ships the tarball. The DC only runs
# `docker load` + `docker compose up -d` — zero network calls beyond
# the initial docker load.

# ─── Stage 1: builder ────────────────────────────────────────────────
# Installs prod deps in a full node image (has python/build-essentials
# just in case a native module needs building — currently `ws` ships
# pre-built optional deps for common arches but we keep the option
# open for future deps).

FROM node:20-alpine AS builder

WORKDIR /workspace/dect-relay-agent

# Copy just the package manifest first so this layer caches across
# code-only changes.
COPY dect-relay-agent/package.json ./package.json

# Install only production deps. --ignore-scripts because we don't run
# arbitrary postinstall from transitive deps in the container build;
# any needed build steps are pinned in this Dockerfile.
RUN npm install --omit=dev --ignore-scripts \
 && npm cache clean --force

# ─── Stage 2: runtime ────────────────────────────────────────────────
# Same base as builder, but only the artifacts we actually need at
# run time (node_modules + agent source + shared integrations + utils).

FROM node:20-alpine AS runtime

# node:20-alpine ships a `node` user (uid 1000) that we can just use —
# no need to install anything extra. Running as a non-root user is a
# baseline hardening we get essentially for free.
USER node

# Match the repo layout so relative imports (`../integrations/...`)
# resolve exactly as they do in development.
WORKDIR /workspace/dect-relay-agent

# Ship the node_modules we built in stage 1. Ownership goes to `node`
# so the process can read them without needing root.
COPY --from=builder --chown=node:node /workspace/dect-relay-agent/node_modules ./node_modules

# Agent source + manifest.
COPY --chown=node:node dect-relay-agent/package.json ./package.json
COPY --chown=node:node dect-relay-agent/index.js ./index.js

# Shared modules the agent imports from the parent workspace.
COPY --chown=node:node integrations/cisco-dect /workspace/integrations/cisco-dect
COPY --chown=node:node utils/httpDigestAuth.js /workspace/utils/httpDigestAuth.js

# Optional metadata that shows up in `docker inspect` output — useful
# in the DC for "which build am I running?" without needing to poke
# inside the container.
ARG AGENT_VERSION=dev
ARG BUILD_DATE
ARG GIT_COMMIT
LABEL org.opencontainers.image.title="dect-relay-agent" \
      org.opencontainers.image.description="Data-center-resident WSS bridge from CollabSupport bot (cloud) to Cisco DBS-210 DECT base stations on 10.x/8" \
      org.opencontainers.image.version="${AGENT_VERSION}" \
      org.opencontainers.image.created="${BUILD_DATE}" \
      org.opencontainers.image.revision="${GIT_COMMIT}" \
      org.opencontainers.image.source="https://git.joesjavajoint.com/jmcqueen/collabSupport"

# Node handles SIGTERM natively when the process installs handlers
# (which we do in index.js). --enable-source-maps improves stack
# traces if something crashes at runtime — cheap and always-on.
CMD ["node", "--enable-source-maps", "index.js"]
