FROM python:3.12-slim

# docker.io provides the Docker CLI; util-linux provides nsenter for host
# namespace access. Both exist for amd64 — verified 2026-07-27.
RUN apt-get update && \
    apt-get install -y --no-install-recommends docker.io util-linux && \
    apt-get clean && \
    rm -rf /var/lib/apt/lists/*

WORKDIR /app

# Pinned install. Every dependency in this tree resolves to a prebuilt
# manylinux x86_64 wheel (pydantic-core, rpds-py, cffi, cryptography), so no
# compiler is needed and the build is fast on amd64.
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

COPY server.py .

EXPOSE 8103

# Fails fast and visibly if the container is up but the app is wedged.
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
  CMD python -c "import urllib.request,os,sys; sys.exit(0 if urllib.request.urlopen('http://127.0.0.1:'+os.environ.get('PORT','8103')+'/health',timeout=3).status==200 else 1)"

CMD ["python", "server.py"]
