# Write Server Dockerfile
# Multi-stage build for production

# Stage 1: Install dependencies
FROM node:20-alpine AS deps
WORKDIR /app

# Copy package files
COPY package.json package-lock.json ./

# Install dependencies
RUN npm ci --only=production && \
    npm cache clean --force

# Stage 2: Build application
FROM node:20-alpine AS builder
WORKDIR /app

# 设置构建时环境变量（Turbopack 会内联这些值）
ENV BLOG_ROOT=/blog

# Copy package files
COPY package.json package-lock.json ./

# Install all dependencies (including devDependencies)
RUN npm ci

# Copy source code
COPY . .

# Build application
RUN npm run build

# Stage 3: Production
FROM node:20-alpine AS runner
WORKDIR /app

# Install system dependencies (gcompat for glibc Hugo binary)
RUN apk add --no-cache git openssh-client su-exec gcompat ffmpeg

# Install Hugo 0.128.2 extended
ARG HUGO_VERSION=0.128.2
RUN wget -q https://github.com/gohugoio/hugo/releases/download/v${HUGO_VERSION}/hugo_extended_${HUGO_VERSION}_linux-amd64.tar.gz -O /tmp/hugo.tar.gz && \
    tar -xzf /tmp/hugo.tar.gz -C /tmp && \
    mv /tmp/hugo /usr/local/bin/hugo && \
    rm /tmp/hugo.tar.gz && \
    hugo version

# Create non-root user
RUN addgroup --system --gid 1001 nodejs && \
    adduser --system --uid 1001 nextjs

# Copy built application
COPY --from=builder /app/public ./public
COPY --from=builder /app/.next/standalone ./
COPY --from=builder /app/.next/static ./.next/static

# Copy production node_modules as fallback (standalone may miss some deps)
COPY --from=deps /app/node_modules ./node_modules

# Copy package.json for version info
COPY --from=builder /app/package.json ./

# Copy entrypoint script
COPY entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh

# Copy password hash script
COPY scripts/hash-users.js /app/scripts/hash-users.js

# Create necessary directories
RUN mkdir -p /app/logs /app/backups /app/recycle/posts /app/recycle/meta

# Expose port
EXPOSE 8016

# Set environment variables
ENV NODE_ENV=production
ENV PORT=8016
ENV HOSTNAME="0.0.0.0"
ENV BLOG_ROOT=/blog

# Health check
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
    CMD wget --no-verbose --tries=1 --spider http://localhost:8016/api/stats || exit 1

# Start application via entrypoint (fixes permissions, drops to nextjs)
ENTRYPOINT ["/entrypoint.sh"]
CMD ["node", "server.js"]
