# Jenkins with a Docker CLI, because every pipeline stage runs in a container
# on the host's daemon (mounted socket) rather than in a Jenkins agent.
FROM jenkins/jenkins:lts-jdk17

USER root

RUN apt-get update && apt-get install -y --no-install-recommends \
        ca-certificates curl gnupg git rsync postgresql-client \
    && install -m 0755 -d /etc/apt/keyrings \
    && curl -fsSL https://download.docker.com/linux/debian/gpg \
         -o /etc/apt/keyrings/docker.asc \
    && chmod a+r /etc/apt/keyrings/docker.asc \
    && echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] \
        https://download.docker.com/linux/debian $(. /etc/os-release && echo $VERSION_CODENAME) stable" \
        > /etc/apt/sources.list.d/docker.list \
    && apt-get update \
    && apt-get install -y --no-install-recommends docker-ce-cli docker-compose-plugin \
    && rm -rf /var/lib/apt/lists/*

# The jenkins user must be in the group that owns /var/run/docker.sock. The
# GID differs per host, so it is passed in at build time (see ci-compose.yml).
ARG DOCKER_GID=999
RUN groupadd -g ${DOCKER_GID} dockerhost || true \
    && usermod -aG ${DOCKER_GID} jenkins

USER jenkins

# Preinstall the plugins the Jenkinsfile depends on so the first boot is not a
# manual click-through.
RUN jenkins-plugin-cli --plugins \
      workflow-aggregator \
      git \
      gitlab-plugin \
      timestamper \
      ansicolor \
      ws-cleanup \
      credentials-binding \
      pipeline-stage-view \
      configuration-as-code
