# syntax=docker/dockerfile:1
FROM node:22-slim

# git: needed to clone/commit/push. ca-certificates: TLS to Gitea/Anthropic.
RUN apt-get update \
    && apt-get install -y --no-install-recommends git ca-certificates \
    && rm -rf /var/lib/apt/lists/* \
    && npm install -g @anthropic-ai/claude-code \
    && npm cache clean --force

WORKDIR /app

# No runtime dependencies today (package.json has none), but this keeps
# the image correct if any are added later, and gets Docker's layer cache.
COPY package.json ./
RUN npm install --omit=dev --no-audit --no-fund || true

COPY src ./src

# Run as an unprivileged user rather than root. The node:*-slim base image
# already ships a "node" user at uid 1000, so reuse it instead of creating
# a new one (useradd at the same uid fails with exit code 4, "UID in use").
RUN chown -R node:node /app
USER node

ENV NODE_ENV=production
EXPOSE 3000

HEALTHCHECK --interval=30s --timeout=5s --start-period=10s \
  CMD node -e "fetch('http://127.0.0.1:'+(process.env.PORT||3000)+'/healthz').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"

CMD ["node", "src/index.js"]
