# syntax=docker/dockerfile:1

# ---- build ----------------------------------------------------------------
FROM mcr.microsoft.com/dotnet/sdk:10.0 AS build
WORKDIR /src

# Restore against the project file alone so the layer caches across code edits.
COPY src/LudosData.Api/LudosData.Api.csproj src/LudosData.Api/
RUN dotnet restore src/LudosData.Api/LudosData.Api.csproj

COPY src/ src/
RUN dotnet publish src/LudosData.Api/LudosData.Api.csproj \
    -c Release \
    -o /app/publish \
    --no-restore \
    /p:UseAppHost=false

# ---- runtime --------------------------------------------------------------
FROM mcr.microsoft.com/dotnet/aspnet:10.0 AS runtime
WORKDIR /app

# The runtime image ships neither curl nor wget, so the container healthcheck
# below has nothing to probe with unless one is added.
RUN apt-get update \
    && apt-get install -y --no-install-recommends curl \
    && rm -rf /var/lib/apt/lists/*

# Run as the non-root user the base image already ships with.
ENV ASPNETCORE_HTTP_PORTS=8080 \
    DOTNET_RUNNING_IN_CONTAINER=true \
    ConnectionStrings__Default="Data Source=/data/ludos.db" \
    Uploads__RootPath=/data/uploads

COPY --from=build /app/publish .

# Writable mount point for the SQLite file and uploaded art. Declared as a volume
# so an unmounted run still persists for the life of the container rather than
# failing to open the database.
RUN mkdir -p /data/uploads && chown -R $APP_UID:$APP_UID /data
VOLUME ["/data"]

USER $APP_UID
EXPOSE 8080

# Probes the app's own health endpoint, so "healthy" means it is actually
# serving requests rather than merely that the process exists.
HEALTHCHECK --interval=30s --timeout=3s --start-period=15s --retries=3 \
    CMD curl -fsS http://localhost:8080/health || exit 1

ENTRYPOINT ["dotnet", "LudosData.Api.dll"]
