# --- Builder Stage ---
# This stage installs all Python dependencies into a virtual environment.
FROM python:3.11 as builder

WORKDIR /opt/venv

# Create a virtual environment
RUN python -m venv .

# Activate the virtual environment and install dependencies
COPY requirements.txt .
RUN . /opt/venv/bin/activate && pip install --no-cache-dir -r requirements.txt


# --- Runner Stage ---
# This stage creates the final, lean image.
FROM python:3.11-slim

# Create a non-privileged user for security
RUN useradd --create-home --shell /bin/bash appuser

WORKDIR /home/appuser/app

# Copy the virtual environment from the builder stage
COPY --from=builder /opt/venv /opt/venv

# Copy the application code
COPY app/ .

# Set the PATH to include the venv binaries
ENV PATH="/opt/venv/bin:$PATH"

# Expose the port the app runs on
EXPOSE 8000

# Switch to the non-privileged user
USER appuser

# Command to run the application using Gunicorn
# This is a production-ready WSGI server.
CMD ["gunicorn", "-k", "uvicorn.workers.UvicornWorker", "-w", "2", "-b", "0.0.0.0:8000", "main:app"]
