# syntax=docker/dockerfile:1.7
# The sandbox in a container, for CI next to your API (docker compose) or a
# shared dev box. Multi-stage: compile with dev deps, ship prod deps + JS.
#
#   docker build -t pay-sandbox .
#   docker run --rm -p 127.0.0.1:4402:4402 pay-sandbox
#
# Inside the container it listens on 0.0.0.0 (so the port can be published).
# It has no sign-in: publish it on 127.0.0.1 or a private network only.

FROM node:22-slim AS build
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci
COPY tsconfig.json tsconfig.build.json ./
COPY src ./src
RUN npm run build

FROM node:22-slim AS runtime
ENV NODE_ENV=production \
    PAY_SANDBOX_PORT=4402 \
    PAY_SANDBOX_HOST=0.0.0.0 \
    PAY_SANDBOX_DIR=/data
WORKDIR /app
COPY package.json package-lock.json ./
RUN npm ci --omit=dev && npm cache clean --force
COPY --from=build /app/dist ./dist
COPY bin ./bin
COPY examples ./examples
# The routes. Rebuild after editing pay-sandbox.yaml, or mount yours at
# /app/pay-sandbox.yaml (it is reloaded when it changes).
COPY pay-sandbox.example.yaml ./pay-sandbox.yaml
# Wallets (and the world, with --persist) live on a volume.
RUN mkdir -p /data && chown node:node /data
VOLUME ["/data"]
USER node
EXPOSE 4402
HEALTHCHECK --interval=15s --timeout=3s --start-period=10s --retries=3 \
  CMD node -e "fetch('http://127.0.0.1:'+(process.env.PAY_SANDBOX_PORT||4402)+'/healthz').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"
# exec form so SIGTERM reaches Node directly.
CMD ["node", "--enable-source-maps", "dist/src/cli.js", "serve", "--config", "pay-sandbox.yaml"]
