# syntax=docker.io/docker/dockerfile:1.27-labs@sha256:ae9cc40df4eb5b6adcac0a49bdd8e43b6d29d81087fefae2ceb6fe248aab24c8
# Context must be the root of the monorepo

# PNPM source
FROM --platform=$BUILDPLATFORM ghcr.io/pnpm/pnpm:12.0.0@sha256:bce5ae25ef95edd79e696d7fa8489b80561ef660100fd35bd0286d0f90db3dcc AS pnpm

# Builder
FROM --platform=$BUILDPLATFORM node:24-bullseye@sha256:25f3016fcdae6b5d65bd9bcb4064b7e4198ec8d49493fa40d73f9b463d04fb15 AS builder

COPY --from=pnpm /opt/pnpm /opt/pnpm
RUN ln -s /opt/pnpm/pnpm /usr/local/bin/pnpm

# Support custom branch of the js-sdk. This also helps us build images of element-web develop.
ARG USE_CUSTOM_SDKS=false
ARG JS_SDK_REPO="https://github.com/matrix-org/matrix-js-sdk.git"
ARG JS_SDK_BRANCH="master"

WORKDIR /src

# Install dependencies
COPY --parents package.json pnpm-lock.yaml pnpm-workspace.yaml patches scripts **/package.json /src/
RUN pnpm install --frozen-lockfile
RUN --mount=type=bind,source=.git,target=/src/.git /src/scripts/docker-link-repos.sh

# Build
COPY --link --exclude=.git --exclude=apps/web/docker . /src
RUN --mount=type=bind,source=.git,target=/src/.git /src/scripts/docker-package.sh

# Copy the config now so that we don't create another layer in the app image
RUN cp /src/apps/web/config.sample.json /src/apps/web/webapp/config.json

# App
FROM nginxinc/nginx-unprivileged:alpine-slim@sha256:c94666682d7ecbfa0a1767fbe882cd1d82509333d15716c765f42bbef0d3809f AS element_web

# Need root user to install packages & manipulate the usr directory
USER root

# Install jq and moreutils for sponge, both used by our entrypoints
RUN apk add jq moreutils

COPY --from=builder /src/apps/web/webapp /app

# Override default nginx config. Templates in `/etc/nginx/templates` are passed
# through `envsubst` by the nginx docker image entry point.
COPY /apps/web/docker/nginx-templates/* /etc/nginx/templates/
COPY /apps/web/docker/docker-entrypoint.d/* /docker-entrypoint.d/

RUN rm -rf /usr/share/nginx/html \
  && ln -s /app /usr/share/nginx/html

# Run as nginx user by default
USER nginx

# HTTP listen port
ENV ELEMENT_WEB_PORT=80

HEALTHCHECK --start-period=5s CMD wget -q --spider http://localhost:$ELEMENT_WEB_PORT/config.json

# Modules are consumed as prebuilt release artifacts rather than built from source.
# Each module is pinned to a version and the sha256 of its release archive.
FROM --platform=$BUILDPLATFORM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS modules

ARG MODULE_BANNER_VERSION=v2.1.1
ADD --checksum=sha256:bd894fa30df4faa4fd7aab450f8d15c2f1b8246b3073b51932e5fa35821973da \
    https://github.com/element-hq/element-web/releases/download/module%2Fbanner%2F${MODULE_BANNER_VERSION}/banner-${MODULE_BANNER_VERSION}.zip \
    /tmp/modules/banner-${MODULE_BANNER_VERSION}.zip

ARG MODULE_RESTRICTED_GUESTS_VERSION=v1.1.0
ADD --checksum=sha256:7669d230bc4a72a9cc76e85c66b88b9b7d209c732484116fbcfd111fa49ce512 \
    https://github.com/element-hq/element-web/releases/download/module%2Frestricted-guests%2F${MODULE_RESTRICTED_GUESTS_VERSION}/restricted-guests-${MODULE_RESTRICTED_GUESTS_VERSION}.zip \
    /tmp/modules/restricted-guests-${MODULE_RESTRICTED_GUESTS_VERSION}.zip

ARG MODULE_WIDGET_LIFECYCLE_VERSION=v1.1.0
ADD --checksum=sha256:2363fdd6bd67e08ac4ca777d11c942559409482c41021e39ff51d5567cc7b76f \
    https://github.com/element-hq/element-web/releases/download/module%2Fwidget-lifecycle%2F${MODULE_WIDGET_LIFECYCLE_VERSION}/widget-lifecycle-${MODULE_WIDGET_LIFECYCLE_VERSION}.zip \
    /tmp/modules/widget-lifecycle-${MODULE_WIDGET_LIFECYCLE_VERSION}.zip

ARG MODULE_WIDGET_TOGGLES_VERSION=v1.1.0
ADD --checksum=sha256:04155cf6885f41643fdecd61559de326d14d5ddf9143ee02041ba1216cbf263d \
    https://github.com/element-hq/element-web/releases/download/module%2Fwidget-toggles%2F${MODULE_WIDGET_TOGGLES_VERSION}/widget-toggles-${MODULE_WIDGET_TOGGLES_VERSION}.zip \
    /tmp/modules/widget-toggles-${MODULE_WIDGET_TOGGLES_VERSION}.zip

# Unpack the modules
RUN apk add --no-cache unzip && \
    for archive in /tmp/modules/*.zip; do \
        name=$(basename "$archive" .zip); \
        mkdir -p "/modules/$name" && unzip -q "$archive" -d "/modules/$name"; \
    done

# Target with element_web + `/modules` copied in
FROM element_web AS element_web_modules

COPY --from=modules /modules /modules
