FROM python:3.11-buster AS builder

WORKDIR /usr/src/cue

RUN pip install virtualenv

ENV VIRTUAL_ENV="/usr/src/cue/env"
RUN virtualenv -p python3.11 $VIRTUAL_ENV
ENV PATH="$VIRTUAL_ENV/bin:$PATH"

COPY requirements-dev.txt ./

# Add stash to known_hosts, so pip installing via git doesn't fail.
RUN mkdir -p /root/.ssh \
  && chmod 0700 /root/.ssh \
  && ssh-keyscan -p 12051 gitlab-master.nvidia.com > /root/.ssh/known_hosts

ARG ssh_prv_key
ARG ssh_pub_key

# In one step: Import SSH keys from host, use them to pull stash-hosted
# dependencies, and then delete the SSH keys.
# This needs to be a single step to prevent docker from creating a layer that
# has someone's private/public SSH keys on them.
RUN echo "$ssh_prv_key" > /root/.ssh/id_rsa \
  && echo "$ssh_pub_key" > /root/.ssh/id_rsa.pub \
  && chmod 600 /root/.ssh/id_rsa \
  && chmod 600 /root/.ssh/id_rsa.pub \
  && pip install --no-cache-dir -r requirements-dev.txt \
  && rm -rf /root/.ssh/

COPY . .

ENV PY_IGNORE_IMPORTMISMATCH=1
ENV PYTHONPATH=.

RUN pdoc --html -o /html cue*


FROM nginx:alpine

# scootch current contents out, so they don't show up in our autoindex list
RUN rm /usr/share/nginx/html/index.html
RUN mkdir /usr/share/nginx/html_50x \
  && mv /usr/share/nginx/html/50x.html /usr/share/nginx/html_50x

COPY --from=builder /html /usr/share/nginx/html
COPY ./scripts/pdoc/nginx/default.conf /etc/nginx/conf.d/default.conf
