# syntax=docker/dockerfile:1
##############################################################################
# WABAS web — production image (internal backend mode).
#
# Runs the full Next.js server with complete node_modules instead of the
# standalone trace: Baileys + @libsql/client are `serverExternalPackages`
# (never bundled), and output-file tracing is notoriously unreliable for
# native .node bindings — the image is larger, but it cannot break at
# runtime because a binary went missing.
#
# Build args (baked into the CLIENT bundle — changing them needs a rebuild):
#   NEXT_PUBLIC_API_MODE       default: internal  (the container IS the backend)
#   NEXT_PUBLIC_API_TIMEOUT_MS default: 15000
#   NEXT_PUBLIC_ENABLE_OUTBOUND_MESSAGES default: 0 (archive-only UI)
#
# Runtime env (change freely, no rebuild):
#   DATABASE_URL, SEED_MODE/SEED_ADMIN_*, WABAS_REAL_INGEST,
#   WABAS_SESSION_KEY, TZ — encrypted media and the session key live under
#   /app/data (mount it); PostgreSQL is external to this image.
##############################################################################

FROM node:22-bookworm-slim AS base
ENV NEXT_TELEMETRY_DISABLED=1
RUN corepack enable
WORKDIR /app

# ---- full deps for the build -----------------------------------------------
FROM base AS deps
COPY .npmrc package.json pnpm-lock.yaml pnpm-workspace.yaml ./
RUN corepack pnpm install --frozen-lockfile

# ---- build ------------------------------------------------------------------
FROM deps AS build
ARG NEXT_PUBLIC_API_MODE=internal
ARG NEXT_PUBLIC_API_TIMEOUT_MS=15000
ARG NEXT_PUBLIC_ENABLE_OUTBOUND_MESSAGES=0
ENV NEXT_PUBLIC_API_MODE=${NEXT_PUBLIC_API_MODE} \
    NEXT_PUBLIC_API_TIMEOUT_MS=${NEXT_PUBLIC_API_TIMEOUT_MS} \
    NEXT_PUBLIC_ENABLE_OUTBOUND_MESSAGES=${NEXT_PUBLIC_ENABLE_OUTBOUND_MESSAGES}
COPY . .
RUN corepack pnpm build

# ---- production-only deps ----------------------------------------------------
FROM base AS prod-deps
COPY .npmrc package.json pnpm-lock.yaml pnpm-workspace.yaml ./
RUN corepack pnpm install --frozen-lockfile --prod

# ---- runner -------------------------------------------------------------------
FROM base AS runner
ENV NODE_ENV=production \
    PORT=3000 \
    NEXT_TELEMETRY_DISABLED=1
# Coolify health probes expect curl or wget to be present.
RUN apt-get update && apt-get install -y --no-install-recommends curl \
    && rm -rf /var/lib/apt/lists/*
# /app/data holds encrypted media files and the local session key — create it
# with the right owner so the named volume inherits it on first mount.
RUN mkdir -p /app/data && chown node:node /app/data

COPY --from=prod-deps --chown=node:node /app/node_modules ./node_modules
COPY --from=build     --chown=node:node /app/.next ./.next
COPY --from=build     --chown=node:node /app/public ./public
COPY --chown=node:node package.json next.config.ts ./
# migrations are read from disk at boot (drizzle migrator), NOT bundled —
# keep the folder next to the binary the same way dev runs it
COPY --chown=node:node src/server/db/migrations ./src/server/db/migrations
# The runtime database seeder reads these JSON files directly from disk.
COPY --chown=node:node src/lib/api/mock/fixtures ./src/lib/api/mock/fixtures

USER node
EXPOSE 3000
VOLUME /app/data

# liveness via the no-auth /api/health route (see src/app/api/health/route.ts)
HEALTHCHECK --interval=30s --timeout=5s --start-period=30s --retries=3 \
  CMD curl --fail --silent http://127.0.0.1:${PORT:-3000}/api/health || exit 1

# `next start` binds 0.0.0.0 and honors $PORT
CMD ["node_modules/.bin/next", "start"]
