# syntax=docker/dockerfile:1
#
# Single image, all six daemons. docker-compose runs one container per daemon
# off this image with a different command — the native-lib + toolchain surface
# is shared, so separate images would duplicate ~all of it. Isolation still
# holds: each daemon is its own container/namespace, only mavend mounts the key
# and the db volume.
#
# Native deps are the prebuilt artifacts the repo already carries under deps/
# (libwhisper+ggml-vulkan, onnxruntime, piper/espeak). We do NOT build
# whisper.cpp from source here — COPY the prebuilt .so and headers.
# ponytail: prebuilt-lib copy, not a from-source build. Add a whisper.cpp build
# stage if you ever need reproducibility / a different arch than the host libs.

FROM golang:1.23-bookworm AS build
WORKDIR /src

# native build inputs (prebuilt libs + headers), then module cache, then source
COPY deps/lib/ /src/deps/lib/
COPY deps/piper/ /src/deps/piper/
COPY deps/include/ /src/deps/include/
COPY deps/whisper.cpp/ggml/include/ /src/deps/whisper.cpp/ggml/include/
COPY go.mod go.sum ./
RUN go mod download
COPY cmd/ ./cmd/
COPY internal/ ./internal/

# CGO wiring mirrors the Makefile; rpath points at the RUNTIME lib location so
# the binaries find their .so at /opt/maven/lib regardless of LD_LIBRARY_PATH.
ENV CGO_ENABLED=1 \
    CGO_CFLAGS="-I/src/deps/include -I/src/deps/whisper.cpp/ggml/include" \
    CGO_LDFLAGS="-L/src/deps/lib -L/src/deps/piper -Wl,-rpath,/opt/maven/lib"
RUN go build -o /out/mavend    ./cmd/mavend    && \
    go build -o /out/mavsttd   ./cmd/mavsttd   && \
    go build -o /out/mavttsd   ./cmd/mavttsd   && \
    go build -o /out/mavweb    ./cmd/mavweb    && \
    go build -o /out/mavpoll   ./cmd/mavpoll   && \
    go build -o /out/mavcaldav ./cmd/mavcaldav

FROM debian:bookworm-slim AS runtime
RUN apt-get update && apt-get install -y --no-install-recommends \
      ca-certificates libvulkan1 mesa-vulkan-drivers libgomp1 && \
    rm -rf /var/lib/apt/lists/*

# runtime native libs: whisper/ggml (incl. vulkan), onnxruntime, piper/espeak.
COPY deps/lib/   /opt/maven/lib/
COPY deps/piper/ /opt/maven/piper/
# piper ships its own .so (onnxruntime, espeak, phonemize) — put them on the path too.
RUN cp -a /opt/maven/piper/*.so* /opt/maven/lib/ 2>/dev/null || true
COPY --from=build /out/ /opt/maven/bin/

ENV LD_LIBRARY_PATH=/opt/maven/lib PATH=/opt/maven/bin:$PATH

# unprivileged; core owns the key + db, modules own nothing.
RUN useradd -r -u 10001 -m maven \
    && mkdir -p /run/maven /var/lib/maven \
    && chown maven:maven /run/maven /var/lib/maven
USER maven
WORKDIR /opt/maven
