# oemer-coskun.de (apps/homepage). Same shape as apps/dashboard/Dockerfile:
# turbo prune, bun install, next build (output: "standalone"), a clean
# runner with server.js + static only. Built and started by
# scripts/deploy/05-release.sh; the container gets NO database credentials
# and no shared env file -- it only talks to api.<domain>/public/*.

# Base image with Bun
FROM oven/bun:1.4.2 AS base

FROM base AS turbo-cli
# Same turbo as the root package.json; an unpinned one changes the pruned
# lockfile under our feet.
RUN bun add -g turbo@2.9.3

# Builder stage - prune homepage workspace
FROM turbo-cli AS builder
WORKDIR /app
COPY . .
RUN turbo prune @midday/homepage --docker

# Installer stage
FROM base AS installer
WORKDIR /app

COPY --from=builder /app/out/json/ .
COPY bunfig.toml .
# Install strictly from the lockfile. turbo prune (2.9.3 and 2.11.4 alike)
# writes bun.lock's tarball entries -- xlsx from cdn.sheetjs.com -- with an
# extra "" field bun cannot parse; bun then ignored the whole lockfile and
# resolved every dependency afresh on each build. The sed repairs that one
# shape (a no-op once turbo fixes it); --frozen-lockfile fails the build if
# the lockfile and the package.json files ever disagree.
RUN sed -E -i 's/(\["[^"]+@https?:\/\/[^"]+"), "", /\1, /' bun.lock \
  && bun install --frozen-lockfile

COPY --from=builder /app/out/full/ .

# NEXT_PUBLIC_* are baked into the client bundle at build time; 05-release.sh
# passes them from the rendered server env file (a change needs a rebuild).
ARG NEXT_PUBLIC_SITE_URL
ARG NEXT_PUBLIC_API_URL
ARG NEXT_PUBLIC_CONTACT_EMAIL
ARG NEXT_PUBLIC_PORTAL_URL

# 05-release.sh stamps .git-commit-sha into the release tree.
COPY --from=builder /app/.git-commit-sha /tmp/git-sha.txt

ENV CI=true
ENV NODE_ENV=production
ENV NEXT_TELEMETRY_DISABLED=1

RUN bunx turbo run build --filter=@midday/homepage --only

# Runner stage - clean bun image, no turbo
FROM oven/bun:1.4.2 AS runner
WORKDIR /app

ENV NODE_ENV=production
ENV PORT=3000
ENV HOSTNAME="0.0.0.0"
ENV NEXT_TELEMETRY_DISABLED=1

RUN groupadd --system --gid 1001 nodejs && \
    useradd --system --uid 1001 --no-log-init -g nodejs nextjs

COPY --from=installer --chown=nextjs:nodejs /app/apps/homepage/.next/standalone ./
COPY --from=installer --chown=nextjs:nodejs /app/apps/homepage/.next/static ./apps/homepage/.next/static
# The landing page's pictures (src/lib/images.ts); standalone does not copy public/.
COPY --from=installer --chown=nextjs:nodejs /app/apps/homepage/public ./apps/homepage/public
# AGPL §13: the source archive of this release and its manifest, served as
# /quellcode/<file> and read by the /quellcode page. Made outside the server
# by scripts/deploy/source-archive.sh (release-images.yml or 05-release.sh)
# into .source-archive/ of the build context; a build without it fails here
# on purpose, like a missing .git-commit-sha.
COPY --from=builder --chown=nextjs:nodejs /app/.source-archive/ ./apps/homepage/public/quellcode/

COPY --from=installer /tmp/git-sha.txt /tmp/git-sha.txt
COPY --from=builder /app/scripts/docker-entrypoint.sh /app/entrypoint.sh
RUN chmod +x /app/entrypoint.sh

USER nextjs

EXPOSE 3000

ENTRYPOINT ["/app/entrypoint.sh"]
CMD ["bun", "apps/homepage/server.js"]
