# ORION-LOGISTICS — Production container
FROM php:8.3-apache

# PHP extensions
RUN docker-php-ext-install pdo pdo_mysql opcache

# Apache: enable rewrite + headers, set docroot
RUN a2enmod rewrite headers
ENV APACHE_DOCUMENT_ROOT=/var/www/html
COPY deploy/apache-vhost.conf /etc/apache2/sites-available/000-default.conf

# Opcache production settings
RUN { \
    echo 'opcache.enable=1'; \
    echo 'opcache.memory_consumption=128'; \
    echo 'opcache.max_accelerated_files=10000'; \
    echo 'opcache.validate_timestamps=0'; \
    echo 'expose_php=Off'; \
    echo 'display_errors=Off'; \
    echo 'log_errors=On'; \
  } > /usr/local/etc/php/conf.d/orion.ini

# App code
COPY . /var/www/html
WORKDIR /var/www/html

# Least-privilege: web user owns only what it must; uploads/logs writable.
RUN chown -R www-data:www-data /var/www/html \
 && mkdir -p /var/www/html/logs /var/www/html/assets/uploads/pods /var/www/html/assets/uploads/receipts /var/www/html/assets/uploads/documents /var/www/html/backups \
 && chmod -R 750 /var/www/html \
 && chmod -R 770 /var/www/html/logs /var/www/html/assets/uploads

# Secrets come from env at runtime, never baked into the image.
EXPOSE 80
HEALTHCHECK --interval=30s --timeout=5s --retries=3 \
  CMD curl -fsS http://localhost/health.php || exit 1
