# ============================================================================
# FlyGuard: ML-ядро обнаружения препятствий в тоннеле метро (Кейс 05, ЛЦТ-2026)
# ============================================================================
FROM python:3.11-slim-bookworm AS base

# System configuration & environment
ENV DEBIAN_FRONTEND=noninteractive \
    PYTHONUNBUFFERED=1 \
    PYTHONDONTWRITEBYTECODE=1 \
    PYTHONPATH="/app:/app/tools" \
    FLYGUARD_DATA="/data"

# Install runtime system dependencies (libgomp1 is required by LightGBM/OpenMP)
RUN apt-get update && apt-get install -y --no-install-recommends \
    libgomp1 \
    ca-certificates \
    && rm -rf /var/lib/apt/lists/*

# Create non-root user and directories
RUN useradd -m -u 1000 -s /bin/bash flyguard && \
    mkdir -p /app /data /app/artifacts && \
    chown -R flyguard:flyguard /app /data

WORKDIR /app

# Cache layer: copy only requirements first
COPY --chown=flyguard:flyguard requirements.txt /app/

# Install python dependencies
RUN pip install --no-cache-dir --upgrade pip && \
    pip install --no-cache-dir -r requirements.txt

# Copy application source code
COPY --chown=flyguard:flyguard . /app/

# Make sure entrypoint script is executable
RUN chmod +x /app/docker-entrypoint.sh

# Switch to non-root user for security
USER flyguard

# Volume mount points
VOLUME ["/data", "/app/artifacts"]

# Container healthcheck
HEALTHCHECK --interval=30s --timeout=10s --start-period=5s --retries=3 \
    CMD python3 -c "import flyguard, numpy, scipy, lightgbm; print('healthy')" || exit 1

ENTRYPOINT ["/app/docker-entrypoint.sh"]
CMD ["test"]
