# =============================================================================
# Kedebah Laravel + Vite web image (finance API/UI, commerce SPA).
# Stage 1 builds the frontend assets; stage 2 is the PHP-FPM + nginx runtime.
# Application source is supplied as the named BuildKit context "app-source";
# this deployment repository remains the main context.
# =============================================================================

# Global build args (must be declared before the first FROM to be usable in
# any FROM line).
ARG PHP_VERSION=8.3

# ---- Stage 1: build Vite assets --------------------------------------------
FROM node:22-bookworm-slim AS assets

# VITE_* values are baked into the compiled bundle at build time.
ARG VITE_APP_NAME=Kedebah
ARG VITE_API_BASE_URL=
ARG VITE_FINANCE_API_URL=
ARG VITE_FINANCE_API_BASE_URL=
ARG VITE_REVERB_APP_KEY=
ARG VITE_REVERB_HOST=
ARG VITE_REVERB_PORT=443
ARG VITE_REVERB_SCHEME=https
ARG VITE_LOGIN_REDIRECT_URL=
ARG VITE_BASE_PATH=/

ENV NODE_OPTIONS=--max-old-space-size=4096

WORKDIR /app
RUN --mount=type=bind,from=app-source,target=/src,ro \
    cp /src/package.json ./ \
 && if [ -f /src/package-lock.json ]; then cp /src/package-lock.json ./; fi
RUN npm ci --no-audit --no-fund || npm install --no-audit --no-fund
# IMPORTANT: use ./vendor and ./node_modules (anchored). A bare --exclude=vendor
# also strips app folders like resources/js/src/components/vendor/.
RUN --mount=type=bind,from=app-source,target=/src,ro \
    tar -C /src \
      --exclude=./.git \
      --exclude=./.env \
      --exclude='./.env.*' \
      --exclude=./vendor \
      --exclude=./node_modules \
      --exclude=./public/build \
      --exclude=./public/hot \
      --exclude=./public/storage \
      --exclude='./storage/logs/*' \
      --exclude='./storage/framework/cache/*' \
      --exclude='./storage/framework/sessions/*' \
      --exclude='./storage/framework/views/*' \
      -cf - . | tar -xf -

# Write a build-time env file that Vite loads for `production` mode.
RUN printf '%s\n' \
    "VITE_APP_NAME=${VITE_APP_NAME}" \
    "VITE_API_BASE_URL=${VITE_API_BASE_URL}" \
    "VITE_FINANCE_API_URL=${VITE_FINANCE_API_URL}" \
    "VITE_FINANCE_API_BASE_URL=${VITE_FINANCE_API_BASE_URL}" \
    "VITE_REVERB_APP_KEY=${VITE_REVERB_APP_KEY}" \
    "VITE_REVERB_HOST=${VITE_REVERB_HOST}" \
    "VITE_REVERB_PORT=${VITE_REVERB_PORT}" \
    "VITE_REVERB_SCHEME=${VITE_REVERB_SCHEME}" \
    "VITE_LOGIN_REDIRECT_URL=${VITE_LOGIN_REDIRECT_URL}" \
    "VITE_BASE_PATH=${VITE_BASE_PATH}" \
    > .env.production

# Build with vite directly (skips vue-tsc so pre-existing TS notes don't block).
RUN npx vite build

# ---- Stage 2: PHP-FPM + nginx runtime --------------------------------------
FROM php:${PHP_VERSION}-fpm-bookworm AS app

ARG INSTALL_CHROMIUM=false

ENV DEBIAN_FRONTEND=noninteractive \
    COMPOSER_ALLOW_SUPERUSER=1 \
    COMPOSER_MEMORY_LIMIT=-1

RUN set -eux; \
    apt-get update; \
    apt-get install -y --no-install-recommends \
        git curl unzip nginx supervisor gosu \
        libpq-dev libpng-dev libjpeg62-turbo-dev libfreetype6-dev \
        libzip-dev libicu-dev libonig-dev libxml2-dev; \
    docker-php-ext-configure gd --with-freetype --with-jpeg; \
    docker-php-ext-install -j"$(nproc)" \
        pdo_pgsql pgsql bcmath gd zip intl exif pcntl opcache; \
    pecl install redis; docker-php-ext-enable redis; \
    if [ "$INSTALL_CHROMIUM" = "true" ]; then \
        apt-get install -y --no-install-recommends \
            chromium fonts-liberation fonts-freefont-ttf nodejs npm ca-certificates; \
    fi; \
    apt-get clean; rm -rf /var/lib/apt/lists/*

COPY --from=composer:2 /usr/bin/composer /usr/bin/composer
# Composer 2.9+ refuses to resolve packages with known advisories when no lock
# file exists. Some module branches ship without composer.lock, so don't block
# the build on advisories (matches versions already running in production).
RUN composer config --global policy.advisories.block false

COPY docker/common/php.ini        /usr/local/etc/php/conf.d/zz-app.ini
COPY docker/common/opcache.ini    /usr/local/etc/php/conf.d/zz-opcache.ini
COPY docker/common/php-fpm.conf   /usr/local/etc/php-fpm.d/zz-www.conf
COPY docker/common/nginx-app.conf /etc/nginx/sites-available/default
COPY docker/common/supervisord.conf /etc/supervisor/conf.d/supervisord.conf
COPY docker/common/entrypoint.sh  /usr/local/bin/entrypoint
RUN chmod +x /usr/local/bin/entrypoint

WORKDIR /var/www/html

RUN --mount=type=bind,from=app-source,target=/src,ro \
    cp /src/composer.json ./ \
 && if [ -f /src/composer.lock ]; then cp /src/composer.lock ./; fi
RUN composer install --no-dev --no-scripts --no-autoloader --prefer-dist --no-interaction || true

RUN --mount=type=bind,from=app-source,target=/src,ro \
    tar -C /src \
      --exclude=./.git \
      --exclude=./.env \
      --exclude='./.env.*' \
      --exclude=./vendor \
      --exclude=./node_modules \
      --exclude=./public/build \
      --exclude=./public/hot \
      --exclude=./public/storage \
      --exclude='./storage/logs/*' \
      --exclude='./storage/framework/cache/*' \
      --exclude='./storage/framework/sessions/*' \
      --exclude='./storage/framework/views/*' \
      -cf - . | tar -xf -
# Bring in the compiled frontend from the assets stage.
COPY --from=assets /app/public/build ./public/build
RUN composer install --no-dev --no-scripts --optimize-autoloader --no-interaction \
 && chown -R www-data:www-data storage bootstrap/cache

EXPOSE 80
ENTRYPOINT ["/usr/local/bin/entrypoint"]
CMD ["/usr/bin/supervisord", "-c", "/etc/supervisor/conf.d/supervisord.conf"]
