# Tablewide's Docmost CE image.
#
# Built by product/docmost/build.sh, never by hand: the build context is an
# upstream Docmost source tree at a pinned commit with tablewide.patch applied
# apps/client/src/ee replaced by make_ee_stub.py's no-op stand-ins, and the
# Enterprise-licensed workspace packages (packages/ee, packages/base-formula)
# removed by drop_ee_packages.py, so no Enterprise-licensed code is compiled
# in. The server's ee/ is an upstream private submodule and is empty in the
# source tarball. build.sh scans the source tree and the finished image for
# Enterprise License text and fails the build on a hit.
#
# An optional build secret "ca" (a PEM bundle) is trusted for package
# downloads, for hosts that reach the registry through a TLS proxy.

FROM node:26-slim AS base
RUN --mount=type=secret,id=ca,required=false \
    if [ -s /run/secrets/ca ]; then export NODE_EXTRA_CA_CERTS=/run/secrets/ca npm_config_cafile=/run/secrets/ca; fi; \
    npm install -g pnpm@11.28.2

FROM base AS builder
WORKDIR /app
COPY . .
RUN --mount=type=secret,id=ca,required=false \
    if [ -s /run/secrets/ca ]; then export NODE_EXTRA_CA_CERTS=/run/secrets/ca npm_config_cafile=/run/secrets/ca; fi; \
    pnpm install --frozen-lockfile
RUN NX_DAEMON=false pnpm build

FROM base AS runtime
# No npm, npx or corepack in the running image.
RUN rm -rf /usr/local/lib/node_modules/corepack /usr/local/bin/corepack /root/.npm
WORKDIR /app
COPY --from=builder /app/apps/server/dist /app/apps/server/dist
COPY --from=builder /app/apps/client/dist /app/apps/client/dist
COPY --from=builder /app/apps/server/package.json /app/apps/server/package.json
COPY --from=builder /app/apps/client/package.json /app/apps/client/package.json
COPY --from=builder /app/packages/editor-ext/dist /app/packages/editor-ext/dist
COPY --from=builder /app/packages/editor-ext/package.json /app/packages/editor-ext/package.json
COPY --from=builder /app/package.json /app/pnpm-lock.yaml /app/pnpm-workspace.yaml /app/
COPY --from=builder /app/patches /app/patches
RUN chown -R node:node /app
USER node
RUN --mount=type=secret,id=ca,required=false,uid=1000 \
    if [ -s /run/secrets/ca ]; then export NODE_EXTRA_CA_CERTS=/run/secrets/ca npm_config_cafile=/run/secrets/ca; fi; \
    pnpm install --frozen-lockfile --prod --filter "./apps/server..." --filter docmost \
    && rm -rf /home/node/.cache/pnpm /home/node/.local/share/pnpm
USER root
RUN rm -rf /usr/local/lib/node_modules/npm /usr/local/bin/npm /usr/local/bin/npx
USER node
RUN mkdir -p /app/data/storage
VOLUME ["/app/data/storage"]
EXPOSE 3000
WORKDIR /app/apps/server
ENV NODE_ENV=production
# Plain node instead of `pnpm start`: about 175 MiB idle instead of 370-400.
CMD ["node", "dist/main"]
