FROM python:3.11-slim AS base

ARG DEBIAN_FRONTEND=noninteractive
ARG JRE_VERSION=17.0.18+10
ARG JRE_DEB="bellsoft-jre${JRE_VERSION}-linux-amd64-full.deb"
ARG JRE_URL=https://download.bell-sw.com/java/${JRE_VERSION}/${JRE_DEB}
ARG INSEL_VERSION=8.3.4.0b
ARG INSEL_DEB="insel_${INSEL_VERSION}_x64_mini.deb"
ARG INSEL_URL=https://insel.eu/download/${INSEL_DEB}

# Java 17 (SimStadt requirement) + INSEL (SimStadt's PV/irradiance workflow steps shell out to it).
# curl is only a build-time dependency to fetch the JRE/INSEL .deb files; it is installed and
# removed within this same layer so it never persists in the final image.
RUN apt-get update && \
    apt-get install curl --no-install-recommends -y && \
    curl ${JRE_URL} -o /tmp/${JRE_DEB} -k && \
    curl ${INSEL_URL} -o /tmp/${INSEL_DEB} -k && \
    apt-get install /tmp/${JRE_DEB} /tmp/${INSEL_DEB} --no-install-recommends -y && \
    apt-get remove curl -y && \
    rm -rf /var/lib/apt/lists/* && \
    apt-get clean && \
    rm /tmp/${JRE_DEB} /tmp/${INSEL_DEB}

RUN groupadd -g 1000 simstadt \
  && useradd simstadt --create-home --shell /bin/bash -u 1000 -g 1000

COPY --from=ghcr.io/astral-sh/uv:0.12.17 /uv /uvx /usr/local/bin/

RUN mkdir -p /opt/venv && chown simstadt:simstadt /opt/venv
ENV VIRTUAL_ENV=/opt/venv
ENV UV_PROJECT_ENVIRONMENT=/opt/venv
ENV PATH="/opt/venv/bin:${PATH}"

USER simstadt
RUN mkdir -p /home/simstadt/app /home/simstadt/Desktop
WORKDIR /home/simstadt/app

FROM base AS cli

# `simstadt` is unpinned (always the latest PyPI release), and `simstadt --install`
# always fetches the latest SimStadt build — there's no version/URL override available
# for either today. This is a deliberate tradeoff for a "real, current" CLI image, not
# an oversight: it means the build needs network access, and rebuilding this stage later
# can silently bake in different simstadt/SimStadt versions than a previous build.
RUN uv venv "$VIRTUAL_ENV" && uv pip install simstadt

RUN simstadt --install

CMD ["simstadt"]

FROM base AS test

COPY --chown=simstadt:simstadt pyproject.toml uv.lock README.md ./
COPY --chown=simstadt:simstadt src ./src
COPY --chown=simstadt:simstadt tests ./tests

RUN uv sync --frozen

RUN simstadt --install

# No `-m "not integration"` filter here, deliberately: this image has a real SimStadt/INSEL
# install (unlike a plain dev machine or CI runner), so its whole point is to run the full
# suite. The `simple_tests` Makefile target remains the one for the non-integration subset.
CMD ["uv", "run", "pytest", "-v"]
