# Build stage
#
# Context is vantagectl/ itself. It used to be the repository root, so that
# shared/ could be copied in beside it; shared is now the private module
# gitea.hostxtra.co.uk/vantage/vantage-shared, fetched like any other
# dependency. The credential for it arrives as a BuildKit secret rather than a
# build arg, which would be baked into this stage's layer history.
FROM golang:1.26 AS builder

WORKDIR /src

ENV GOPRIVATE=gitea.hostxtra.co.uk/*

# Manifests first so the dependency layer caches independently of source edits.
COPY go.mod go.sum ./
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    go mod download

COPY . .

ARG VERSION=dev
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    CGO_ENABLED=0 GOOS=linux go build \
      -ldflags="-s -w -X main.Version=${VERSION}" -o /vantagectl .

# Staged so the scratch image below can have a /tmp. It cannot mkdir one
# itself — scratch has no shell.
RUN mkdir -p /staging/tmp && chmod 1777 /staging/tmp

# Runtime stage
FROM scratch

COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/

# restore extracts an archive here before verifying its checksums, and backup
# stages nothing but still inherits os.MkdirTemp's requirements. Without this
# every restore stops at "temp dir: stat /tmp: no such file or directory".
COPY --from=builder /staging/tmp /tmp
COPY --from=builder /vantagectl /vantagectl

ENTRYPOINT ["/vantagectl"]
