FROM python:3.12-slim

WORKDIR /app/code

# Install dependencies
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

# Copy app
COPY app/ ./app/
COPY sweep.sh /app/code/sweep.sh
RUN chmod +x /app/code/sweep.sh

# Run as root (the base image default). Cloudron's sandboxing (read-only
# rootfs, AppArmor, dropped capabilities) still applies to root inside the
# container, and /app/data is mounted as a root-owned volume, so running as
# root is required for the app to write its SQLite store there.
RUN mkdir -p /app/data

EXPOSE 8000

CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8000"]
