# One small image runs the whole game: a zero-dependency Node server that
# serves the static frontend and lists the installed themes/languages.
FROM node:24-alpine

ENV NODE_ENV=production \
    PORT=8080

WORKDIR /app

# Files stay owned by root and read-only for the runtime user: the app can't modify itself.
COPY package.json ./
COPY server ./server
COPY public ./public

# Run as the unprivileged "node" user (uid 1000) that ships with the image.
USER node

EXPOSE 8080

HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
  CMD ["node", "-e", "fetch('http://127.0.0.1:' + process.env.PORT + '/healthz').then(r => process.exit(r.ok ? 0 : 1), () => process.exit(1))"]

CMD ["node", "server/index.js"]
