# Node 24 to match local development: package-lock.json written by a local `npm install`
# (npm 11) must also pass `npm ci` here, or the build fails with "lock file out of sync".

# 1. Build Stage
FROM node:24-alpine AS build

WORKDIR /app

# Copy dependency files
COPY package*.json ./

# Install dependencies
RUN npm ci --no-audit --no-fund

# Copy source code
COPY . .

# Build with node-server preset (not cloudflare-module)
RUN NITRO_PRESET=node-server npm run build

# 2. Production Stage
FROM node:24-alpine

WORKDIR /app

ENV NODE_ENV=production
ENV PORT=3000
ENV HOST=0.0.0.0

# The Nitro output is self-contained (dependencies are bundled), so nothing else is copied.
COPY --from=build --chown=node:node /app/.output ./.output

# Run as the image's unprivileged user rather than root.
USER node

EXPOSE 3000

# Lets Dokploy/Docker see when the server is actually answering requests.
HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
  CMD wget -qO- http://127.0.0.1:3000/ >/dev/null || exit 1

CMD ["node", ".output/server/index.mjs"]
