# Context is admin/ itself. It used to be the repository root, so that
# shared/ could be copied in beside it; shared is now the private module
# gitea.hostxtra.co.uk/vantage/vantage-shared, fetched like any other
# dependency. The credential for it arrives as a BuildKit secret rather than a
# build arg, which would be baked into this stage's layer history.
FROM golang:1.26-alpine AS builder

WORKDIR /src

ENV GOPRIVATE=gitea.hostxtra.co.uk/*
RUN apk add --no-cache git

COPY go.mod go.sum ./
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    go mod download

COPY . .

RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /out/admin ./cmd
RUN --mount=type=secret,id=netrc,target=/root/.netrc \
    CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /out/adminctl ./cmd/adminctl

FROM alpine:3.20 AS runner

RUN apk add --no-cache ca-certificates && \
    addgroup --system --gid 1001 admin && \
    adduser --system --uid 1001 --ingroup admin admin

COPY --from=builder /out/admin /usr/local/bin/admin
COPY --from=builder /out/adminctl /usr/local/bin/adminctl

USER admin

EXPOSE 8083
ENV PORT=8083

CMD ["/usr/local/bin/admin"]
