# Stage 1 — build
FROM node:22-alpine AS builder

WORKDIR /app

COPY package*.json ./

# `npm ci`, with no `|| npm install` fallback.
#
# That fallback was here and it is worse than the error it hides. `npm ci`
# fails only when package-lock.json disagrees with package.json — exactly the
# case where falling back to `npm install` resolves fresh versions the lock file
# never pinned, so the deployed bundle is built from dependencies nobody chose
# and nobody can reproduce.
#
# When this line fails, the fix is `npm install` locally and COMMIT the updated
# package-lock.json. The build should not paper over a lock file that is out of
# date; it should say so.
RUN npm ci --no-audit --no-fund

COPY . .
RUN npm run build

# Stage 2 — serve
FROM nginx:alpine

# The config is a TEMPLATE, and that is deliberate.
#
# nginx:alpine's entrypoint runs `envsubst` over /etc/nginx/templates/*.template
# at container start and writes the result into conf.d. That is how the ingest
# API key reaches nginx as a runtime environment variable rather than being
# committed here in plain text — which is what the previous Dockerfile did with
# the Hasura secret, on the line this replaces.
COPY nginx.conf.template /etc/nginx/templates/default.conf.template

# Restricts substitution to this one name.
#
# Without the filter, envsubst replaces every `${...}` it recognises as an
# environment variable — and the container's environment carries HOSTNAME, PATH
# and friends. Nginx's own `$uri`, `$remote_addr` and `$proxy_add_x_forwarded_for`
# would survive that today, but only by luck, and a config silently rewritten at
# boot is a bad thing to leave to luck.
ENV NGINX_ENVSUBST_FILTER=INGEST_TOKEN

# Empty by default, so the image runs without it. Sheet upload then fails with
# the ingest service's own 401, which says what is missing — rather than nginx
# refusing to start and taking the whole console down with it.
ENV INGEST_TOKEN=""

COPY --from=builder /app/dist/ /usr/share/nginx/html/

EXPOSE 80

CMD ["nginx", "-g", "daemon off;"]
