# Context is sitesvc/ itself. It used to be the repository root, so that
# shared/ could be copied in beside it; shared is now the private module
# gitea.hostxtra.co.uk/vantage/vantage-shared, fetched like any other
# dependency. The credential for it arrives as a BuildKit secret rather than a
# build arg, which would be baked into this stage's layer history.
FROM golang:1.26-alpine AS builder

WORKDIR /src

ENV GOPRIVATE=gitea.hostxtra.co.uk/*
RUN apk add --no-cache git

COPY go.mod go.sum ./
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    go mod download

COPY . .

RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /out/sitesvc ./cmd

FROM alpine:3.20 AS runner

# Needed to verify the SMTP server's TLS certificate.
RUN apk add --no-cache ca-certificates && \
    addgroup --system --gid 1001 sitesvc && \
    adduser --system --uid 1001 --ingroup sitesvc sitesvc

COPY --from=builder /out/sitesvc /usr/local/bin/sitesvc

USER sitesvc

EXPOSE 8082
ENV PORT=8082

CMD ["/usr/local/bin/sitesvc"]
