FROM pandoc/typst:latest-alpine AS typst

FROM node:22-alpine

# Enable corepack and activate pnpm
RUN corepack enable && corepack prepare pnpm@11.3.0 --activate

# pm2 manages the process; sequelize-cli runs migrations on startup
RUN npm install -g pm2 sequelize-cli

# Typst — compiles certificate.typ into the downloadable PDF certificate.
# Not available as an apk package, so lift the binary out of pandoc/typst.
COPY --from=typst /usr/bin/typst /usr/local/bin/typst

WORKDIR /app

# Install production dependencies only
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml ./
RUN pnpm install --frozen-lockfile

COPY . .

RUN chmod +x docker-entrypoint.sh

EXPOSE 3024

ENTRYPOINT ["./docker-entrypoint.sh"]
