# syntax=docker/dockerfile:1
# Build the Gatus binary from the vendored source in ./src
FROM golang:alpine AS builder
RUN apk --no-cache add ca-certificates tzdata
WORKDIR /app
COPY src/go.mod src/go.sum ./
RUN go mod download
COPY src/ ./
RUN CGO_ENABLED=0 GOOS=linux go build -trimpath -ldflags="-s -w" -o gatus .
# Pre-create a directory we can hand to the scratch stage with the right owner
# (used as the mount point for sqlite storage volumes)
RUN mkdir /data && chown 65534:65534 /data

# Run the binary on an empty container
FROM scratch
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ca-certificates.crt
COPY --from=builder /usr/share/zoneinfo /usr/share/zoneinfo
COPY --from=builder /app/gatus /gatus
COPY --from=builder --chown=65534:65534 /data /data
# Default config baked in; overridden by a bind mount (compose) or ConfigMap (helm)
COPY config/config.yaml /config/config.yaml

# Gatus reads /config/config.yaml by default when GATUS_CONFIG_PATH is empty
ENV GATUS_CONFIG_PATH="" \
    GATUS_LOG_LEVEL="INFO" \
    PORT="8080"
EXPOSE 8080

# nobody:nogroup — note: ICMP (icmp://) endpoints require root or CAP_NET_RAW
USER 65534:65534
ENTRYPOINT ["/gatus"]
