# ---- Build stage ----
FROM node:22-alpine AS build

WORKDIR /app

# Safety valve for the 2 GB host: without a cap a runaway build can exhaust the
# server's RAM and take down neighbouring containers, so the build fails instead
# of the server.
#
# Headroom is thinner than it used to be. The old note here recorded a ~550 MB
# peak; after the React 19 upgrade and adding Astryx the build measures ~967 MB
# peak RSS, which still completes under this cap but no longer leaves much room.
# If a future dependency tips it over, raise this only alongside more host RAM —
# not on its own, which just moves the failure from the build to the machine.
ENV NODE_OPTIONS=--max-old-space-size=1024

# Install deps from the lockfile first so this layer is reused when only src changes
COPY package.json package-lock.json ./
RUN npm ci --no-audit --no-fund

COPY . .
RUN npm run build

# ---- Runtime stage ----
FROM nginx:alpine

# Remove Nginx's default "Welcome" page files completely
RUN rm -rf /usr/share/nginx/html/*

# Only the compiled assets reach the final image — no node_modules, no source
COPY --from=build /app/dist /usr/share/nginx/html

COPY nginx.conf /etc/nginx/nginx.conf

EXPOSE 80 3000

CMD ["nginx", "-g", "daemon off;"]
