# =============================================================================
# Kedebah Laravel API image (auth, onboarding, tenant-processor, email, sms).
# No frontend build. The application source is supplied as the named BuildKit
# context "app-source"; this deployment repository remains the main context.
# =============================================================================
# PHP version is a build arg because some module lock files were generated on
# newer PHP (e.g. tenant-processor locks Symfony 8 -> needs PHP 8.4).
ARG PHP_VERSION=8.3
FROM php:${PHP_VERSION}-fpm-bookworm AS app

ARG INSTALL_PG_CLIENT=false

ENV DEBIAN_FRONTEND=noninteractive \
    COMPOSER_ALLOW_SUPERUSER=1 \
    COMPOSER_MEMORY_LIMIT=-1

# --- System deps + PHP extensions -------------------------------------------
RUN set -eux; \
    apt-get update; \
    apt-get install -y --no-install-recommends \
        git curl unzip nginx supervisor gosu \
        libpq-dev libpng-dev libjpeg62-turbo-dev libfreetype6-dev \
        libzip-dev libicu-dev libonig-dev libxml2-dev; \
    docker-php-ext-configure gd --with-freetype --with-jpeg; \
    docker-php-ext-install -j"$(nproc)" \
        pdo_pgsql pgsql bcmath gd zip intl exif pcntl opcache; \
    pecl install redis; docker-php-ext-enable redis; \
    if [ "$INSTALL_PG_CLIENT" = "true" ]; then \
        apt-get install -y --no-install-recommends postgresql-client; \
    fi; \
    apt-get clean; rm -rf /var/lib/apt/lists/*

# --- Composer ----------------------------------------------------------------
COPY --from=composer:2 /usr/bin/composer /usr/bin/composer
# Composer 2.9+ refuses to resolve packages with known advisories when no lock
# file exists. Some module branches ship without composer.lock, so don't block
# the build on advisories (matches versions already running in production).
RUN composer config --global policy.advisories.block false

# --- PHP / FPM config --------------------------------------------------------
COPY docker/common/php.ini        /usr/local/etc/php/conf.d/zz-app.ini
COPY docker/common/opcache.ini    /usr/local/etc/php/conf.d/zz-opcache.ini
COPY docker/common/php-fpm.conf   /usr/local/etc/php-fpm.d/zz-www.conf
COPY docker/common/nginx-app.conf /etc/nginx/sites-available/default
COPY docker/common/supervisord.conf /etc/supervisor/conf.d/supervisord.conf
COPY docker/common/entrypoint.sh  /usr/local/bin/entrypoint
RUN chmod +x /usr/local/bin/entrypoint

WORKDIR /var/www/html

# --- Dependencies (cached layer) --------------------------------------------
RUN --mount=type=bind,from=app-source,target=/src,ro \
    cp /src/composer.json ./ \
 && if [ -f /src/composer.lock ]; then cp /src/composer.lock ./; fi
RUN composer install --no-dev --no-scripts --no-autoloader --prefer-dist --no-interaction || true

# --- Application source ------------------------------------------------------
# Copy from the external repository while explicitly excluding local secrets,
# generated dependencies, runtime files, and VCS metadata.
# IMPORTANT: use ./vendor (anchored). A bare --exclude=vendor also strips
# application folders named vendor/ (e.g. Vue components).
RUN --mount=type=bind,from=app-source,target=/src,ro \
    tar -C /src \
      --exclude=./.git \
      --exclude=./.env \
      --exclude='./.env.*' \
      --exclude=./vendor \
      --exclude=./node_modules \
      --exclude=./public/build \
      --exclude=./public/hot \
      --exclude=./public/storage \
      --exclude='./storage/logs/*' \
      --exclude='./storage/framework/cache/*' \
      --exclude='./storage/framework/sessions/*' \
      --exclude='./storage/framework/views/*' \
      -cf - . | tar -xf -
RUN composer install --no-dev --no-scripts --optimize-autoloader --no-interaction \
 && chown -R www-data:www-data storage bootstrap/cache

EXPOSE 80
ENTRYPOINT ["/usr/local/bin/entrypoint"]
CMD ["/usr/bin/supervisord", "-c", "/etc/supervisor/conf.d/supervisord.conf"]
