# syntax=docker/dockerfile:1

# ── build ───────────────────────────────────────────────────────────────────
# templ output (*_templ.go) and the vendored htmx asset are committed, so a
# plain `go build` produces a self-contained binary — no codegen, no CDN.
FROM golang:1.26 AS build

WORKDIR /src

COPY go.mod go.sum ./
RUN go mod download

COPY . .

# CGO off + static linking so the binary runs in a distroless/scratch image with
# no libc. Trim symbols/DWARF to shrink the layer.
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags='-s -w' -o /out/tapir ./cmd/tapir

# ── runtime ─────────────────────────────────────────────────────────────────
# distroless static + nonroot: no shell, no package manager, runs as uid 65532.
# ca-certificates are bundled, which the OIDC/HTTPS clients need.
FROM gcr.io/distroless/static-debian12:nonroot

COPY --from=build /out/tapir /tapir

EXPOSE 8080
USER nonroot:nonroot
ENTRYPOINT ["/tapir"]
CMD ["serve"]
