# Abhaengigkeiten in ein venv bauen, damit der Compiler-Ballast nicht ins
# fertige Image wandert.
FROM python:3.12-slim AS build
WORKDIR /app
RUN python -m venv /opt/venv
ENV PATH="/opt/venv/bin:$PATH"
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

# Testlauf gegen dieselbe Python-Version und dieselben Pakete wie die
# Produktion. Die Stufe haengt nicht am finalen Image und wird bei einem
# normalen Build uebersprungen; der Workflow ruft sie mit --target test auf.
FROM build AS test
RUN apt-get update \
    && apt-get install -y --no-install-recommends libglib2.0-0 \
    && rm -rf /var/lib/apt/lists/*
COPY requirements-dev.txt .
RUN pip install --no-cache-dir -r requirements-dev.txt
COPY app ./app
COPY static ./static
COPY tests ./tests
RUN pytest -q

FROM python:3.12-slim
ENV PYTHONUNBUFFERED=1 \
    PYTHONDONTWRITEBYTECODE=1 \
    PATH="/opt/venv/bin:$PATH" \
    DATA_DIR=/data

# libglib2.0-0 wird von opencv-python-headless gebraucht.
RUN apt-get update \
    && apt-get install -y --no-install-recommends libglib2.0-0 \
    && rm -rf /var/lib/apt/lists/* \
    && useradd --uid 10001 --create-home app \
    && mkdir -p /data && chown app:app /data

COPY --from=build /opt/venv /opt/venv
WORKDIR /app
COPY app ./app
COPY static ./static

USER app
EXPOSE 8080
CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8080"]
