# The public guest site (HDTOOL_MODE=guest) for Cloud Run.
#
# Build context must contain source.tar.gz, the AGPL source offered at /source.tar.gz;
# the GitHub Actions workflow makes it with `git archive` before building.
# pyswisseph has no Linux wheel, so it is compiled in a throwaway stage.

FROM python:3.12-slim AS build
RUN apt-get update \
    && apt-get install -y --no-install-recommends build-essential \
    && rm -rf /var/lib/apt/lists/*
COPY requirements.txt /tmp/requirements.txt
RUN pip wheel --no-cache-dir --wheel-dir /wheels -r /tmp/requirements.txt

FROM python:3.12-slim
ENV PYTHONDONTWRITEBYTECODE=1 \
    PYTHONUNBUFFERED=1 \
    HDTOOL_MODE=guest \
    HDTOOL_SOURCE_ARCHIVE=/app/source.tar.gz \
    HDTOOL_PUBLIC_URL=https://fate.charlestw.com \
    PORT=8080
COPY --from=build /wheels /wheels
RUN pip install --no-cache-dir /wheels/* && rm -rf /wheels \
    && useradd --create-home --uid 10001 app
WORKDIR /app
COPY hdtool ./hdtool
COPY source.tar.gz ./source.tar.gz
USER app
# No access log: result URLs carry birth dates and times.
CMD ["sh", "-c", "exec uvicorn hdtool.webapp:app --host 0.0.0.0 --port ${PORT} --no-access-log"]
