# Two stages: the runtime image carries the binary and nothing else.
# Must match the `go` directive in go.mod. A lower builder fails with
# "go.mod requires go >= X" because GOTOOLCHAIN=local inside the image - the
# local build hid this by silently downloading a newer toolchain.
FROM golang:1.25-alpine AS build
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
ARG VERSION=dev
# CGO off gives a static binary, which is what makes the scratch-like runtime
# below possible and removes the whole class of glibc/musl surprises.
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath \
    -ldflags "-s -w -X main.version=${VERSION}" \
    -o /out/behavision-server ./cmd/behavision-server

FROM alpine:3.20
# ca-certificates for outbound TLS (object storage, webhooks). tzdata because
# footfall is reported in each site's local time and the container's default
# UTC-only image would make every report an hour or more wrong.
RUN apk add --no-cache ca-certificates tzdata && \
    adduser -D -u 10001 behavision
COPY --from=build /out/behavision-server /usr/local/bin/behavision-server
USER behavision
EXPOSE 8080
ENTRYPOINT ["/usr/local/bin/behavision-server"]
