# Multi-stage build for the read-only Next.js UI (FR-11.1 / NFR-5.1).
# Binds 0.0.0.0:9101 inside the container so the docker-compose host map
# `127.0.0.1:9101->9101` (the actual localhost-only gate) can reach it.

FROM node:20-alpine AS deps
WORKDIR /app
COPY package.json ./
RUN npm install --no-audit --no-fund

FROM node:20-alpine AS builder
WORKDIR /app
COPY --from=deps /app/node_modules ./node_modules
COPY . .
RUN npm run build

FROM node:20-alpine AS runner
WORKDIR /app
ENV NODE_ENV=production
ENV HOSTNAME=0.0.0.0
ENV PORT=9101
COPY --from=builder /app/.next/standalone ./
COPY --from=builder /app/.next/static ./.next/static
COPY --from=builder /app/public ./public
EXPOSE 9101
CMD ["node", "server.js"]
