# syntax=docker/dockerfile:1.7
#
# Grape peer image. Single multi-stage build that produces the grapepeer,
# txgen, and secret binaries on a slim Alpine runtime.
#
# The default Java VM runs as a sibling container over gRPC. The opt-in Geth
# development backend is embedded in the peer; see docs/GETH-INTEGRATION.md.

ARG GO_VERSION=1.26.8
ARG ALPINE_VERSION=3.20

# -----------------------------------------------------------------------------
# Builder
# -----------------------------------------------------------------------------
FROM golang:${GO_VERSION}-alpine AS builder

RUN apk add --no-cache git ca-certificates build-base

WORKDIR /src

# Cache module downloads.
COPY go.mod go.sum ./
RUN go mod download

# Bring in the rest of the source.
COPY . .

# Build all entry points. CGO is off so the binaries are static and the
# runtime image stays minimal.
ENV CGO_ENABLED=0 GOOS=linux GOFLAGS="-trimpath"
ARG VERSION=dev
ARG LDFLAGS="-s -w -X github.com/Grape-Chain/Grape-Dag/version.Version=${VERSION}"
RUN go build -ldflags="${LDFLAGS}" -o /out/grapepeer ./cmd/grapepeer && \
    go build -ldflags="${LDFLAGS}" -o /out/txgen    ./cmd/txgen    && \
    go build -ldflags="${LDFLAGS}" -o /out/secret   ./cmd/secret

# -----------------------------------------------------------------------------
# Runtime
# -----------------------------------------------------------------------------
FROM alpine:${ALPINE_VERSION}

RUN apk add --no-cache bash ca-certificates curl openssl tini && \
    addgroup -S grape && adduser -S -G grape -u 1000 grape && \
    mkdir -p /home/grape/.grap3 && \
    chown -R grape:grape /home/grape

# Default config templates. Operators are expected to mount their own
# overrides at /home/grape/.grap3 in production.
COPY --chown=grape:grape config/grapepeer-smc.yml      /home/grape/.grap3/grapepeer.yml
COPY --chown=grape:grape config/txgenerator.yml       /home/grape/.grap3/txgenerator.yml
COPY --chown=grape:grape config/bootstrap.json        /home/grape/.grap3/bootstrap.json
COPY --chown=grape:grape config/grapepk.json          /home/grape/.grap3/grapepk.json

# Binaries.
COPY --from=builder /out/grapepeer /usr/local/bin/grapepeer
COPY --from=builder /out/txgen    /usr/local/bin/txgen
COPY --from=builder /out/secret   /usr/local/bin/secret

COPY --chown=grape:grape deploy/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN sed -i 's/\r$//' /usr/local/bin/entrypoint.sh && chmod +x /usr/local/bin/entrypoint.sh

USER grape
WORKDIR /home/grape

# REST API, gRPC, and libp2p ports. Adjust to your config.
EXPOSE 8010 33331 39399

ENTRYPOINT ["/sbin/tini", "--", "/usr/local/bin/entrypoint.sh"]
CMD ["grapepeer"]
