# Electronics Catalog API - production image.
#
#   docker build -t electronics-catalog-api backend/
#   docker run -d --name electronics-catalog-api -p 8000:8000 \
#       --env-file backend/.env.production --restart unless-stopped electronics-catalog-api
#
# No secrets are baked in: .env / .env.production are excluded by .dockerignore
# and every setting arrives through the container environment (the platform's
# Environment tab, or --env-file). See .env.production.example for the list.
FROM python:3.13-slim

ENV PYTHONDONTWRITEBYTECODE=1 \
    PYTHONUNBUFFERED=1 \
    PIP_NO_CACHE_DIR=1 \
    PIP_DISABLE_PIP_VERSION_CHECK=1

WORKDIR /app

COPY requirements-api.txt .
RUN pip install -r requirements-api.txt

COPY app ./app

# Run as an unprivileged user; the app writes nothing to disk.
RUN useradd --create-home --uid 10001 appuser
USER appuser

EXPOSE 8000

HEALTHCHECK --interval=30s --timeout=5s --start-period=20s --retries=3 \
    CMD python -c "import urllib.request,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:8000/api/health', timeout=4).status == 200 else 1)"

CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000", "--proxy-headers", "--forwarded-allow-ips", "*"]
