# ============================================
# Stage 1: Build Flutter Web Application
# ============================================
FROM ghcr.io/cirruslabs/flutter:stable AS web-builder

USER root

WORKDIR /app

# Safe directory configuration for git
RUN git config --global --add safe.directory /app

# Optimize DART VM Memory for build to prevent OOM
ENV DART_VM_OPTIONS="--old_gen_heap_size=4096"

# Enable web support (idempotent)
RUN flutter config --enable-web

# Force cache invalidation when source changes (update this value to force rebuild)
ARG CACHEBUST=2026-03-09-epg-v1

# Copy dependency files first for better caching
COPY pubspec.yaml ./

# Get dependencies
RUN flutter pub get

# Copy source code
COPY . .

# Re-run pub get
RUN flutter pub get

# Generate code
RUN dart run build_runner build --delete-conflicting-outputs

# Clean build environment
RUN flutter clean

# Build web application
RUN flutter build web --release --base-href="/" --no-wasm-dry-run --no-tree-shake-icons --verbose

# ============================================
# Stage 2: Compile Configurable Server (Native)
# ============================================
# Server has its own pubspec.yaml in bin/ directory with shelf, shelf_router, etc.
# We use dart:stable here since bin/pubspec.yaml does NOT depend on Flutter SDK
FROM dart:stable AS server-builder

WORKDIR /app

# Copy server-specific pubspec and source files
# NOTE: bin/ has its own pubspec.yaml with server dependencies
COPY bin/ ./bin/
# lib/ is needed for shared models between frontend and backend
COPY lib/ ./lib/

# Get server dependencies (from bin/pubspec.yaml)
WORKDIR /app/bin
RUN dart pub get

# Compile server to native executable
RUN dart compile exe server.dart -o server

# ============================================
# Stage 3: Production Runtime (with NVENC support)
# ============================================
FROM debian:stable-slim

# Install runtime dependencies, tools for fetching FFmpeg, and gosu for privilege dropping
RUN apt-get update && apt-get install -y --no-install-recommends \
    ca-certificates \
    sqlite3 \
    libsqlite3-dev \
    curl \
    wget \
    xz-utils \
    gosu \
    && rm -rf /var/lib/apt/lists/*

# Install FFmpeg with NVIDIA NVENC support from BtbN static builds
# Falls back gracefully to CPU if GPU not available
RUN wget -q https://github.com/BtbN/FFmpeg-Builds/releases/download/latest/ffmpeg-master-latest-linux64-gpl.tar.xz \
    && tar xf ffmpeg-master-latest-linux64-gpl.tar.xz \
    && mv ffmpeg-master-latest-linux64-gpl/bin/ffmpeg /usr/local/bin/ \
    && mv ffmpeg-master-latest-linux64-gpl/bin/ffprobe /usr/local/bin/ \
    && rm -rf ffmpeg-master-latest-linux64-gpl* \
    && chmod +x /usr/local/bin/ffmpeg /usr/local/bin/ffprobe

# Create non-root user for security
RUN groupadd -r xtremuser && useradd -r -g xtremuser -G audio,video xtremuser

WORKDIR /app

# Create necessary data directories with correct permissions
RUN mkdir -p /app/data /app/web /app/recordings /tmp/xtremflow_streams \
    && chown -R xtremuser:xtremuser /app /tmp/xtremflow_streams

# Copy built artifacts
COPY --from=web-builder /app/build/web /app/web
COPY --from=server-builder /app/bin/server /app/server

# Copy entrypoint script and set permissions
COPY entrypoint.sh /app/entrypoint.sh
RUN chmod +x /app/server /app/entrypoint.sh

# NOTE: We stay as root to allow entrypoint.sh to fix volume permissions
# The entrypoint script will drop privileges to xtremuser after fixing permissions

# Expose port
EXPOSE 8089

# Healthcheck
HEALTHCHECK --interval=30s --timeout=3s \
    CMD curl -f http://localhost:8089/index.html || exit 1

# Use entrypoint to fix permissions then start server as xtremuser
ENTRYPOINT ["/app/entrypoint.sh"]
CMD ["/app/server", "--port", "8089", "--path", "/app/web"]
