# Containerfile — the inbound channels airlock, as a Lambda container image.
#
# Reference-tier (channels/ADAPTERS.md §"Reference bindings"): the base image a
# consumer FROMs to add its own ChannelsManifest (see examples/webhook_peer/).
#
# Build from the REPO ROOT (the build context is the repo root so `safe_agents`
# and pyproject are visible), targeting arm64 to match the Lambda arch:
#   podman build --platform linux/arm64 \
#     -t safe-agents-channels-airlock:dev \
#     -f safe_agents/channels/airlock/Containerfile .
#
# The third-party base is pinned by digest, and the tag is kept only so a reader can
# see which image the digest names. The digest is the multi-arch index, so a
# linux/arm64 build and a linux/amd64 build both resolve through it.
# Re-resolve: skopeo inspect --raw docker://public.ecr.aws/lambda/python:3.13 | shasum -a 256
FROM public.ecr.aws/lambda/python:3.13@sha256:bbbeda2232ecd79f0ef44fa92799cbd7faf0b285376b2ba53bea292c8255ccd8

# Install the safe-agents SDK (+ the `aws` extra for boto3) into the image, in the
# same two steps as safe_agents/arms/local/Containerfile.broker. pyproject.toml
# declares what the SDK needs; the lock files under requirements/ fix which version
# of each package this image gets (CONTRIBUTING.md, "The lock files"), and nothing
# is resolved at build time.
#
# Third-party packages go in first, from two hash-checked locks. requirements/aws.txt
# is the runtime dependencies (pydantic, PyYAML, cryptography, whenever) plus the
# `aws` extra. requirements/build-backend.txt is setuptools, which builds the SDK
# from the COPY'd source. The SDK itself then installs with --no-index, so that step
# downloads nothing and fails, naming the requirement, when pyproject.toml asks for
# something the locks lack.
#
# The locks are compiled for Python 3.12 and later, so their hashes include the
# wheels this image's Python 3.13 selects. WORKDIR is the Lambda task root
# (/var/task) in this base image.
COPY requirements/aws.txt requirements/build-backend.txt ./requirements/
RUN pip install --no-cache-dir --require-hashes \
      -r requirements/aws.txt -r requirements/build-backend.txt
COPY pyproject.toml README.md LICENSE ./
COPY safe_agents ./safe_agents
RUN pip install --no-cache-dir --no-index --no-build-isolation --check-build-dependencies ".[aws]"

# The Lambda runtime imports this dotted path and calls handler(event, context).
CMD ["safe_agents.channels.airlock.handler.handler"]
