# personal-learn — content server + KB demo UI for agOS url-ingestion
FROM python:3.11-slim AS runtime

WORKDIR /app

COPY requirements.txt ./
RUN pip install --no-cache-dir -r requirements.txt

# Application + baked normalized corpus (the /kb artifacts agOS ingests).
# Original media (/files videos) are NOT baked — served from a volume/object
# store later; video deep-links resolve once that is mounted.
COPY server.py ./
COPY _kb_corpus/ ./_kb_corpus/

# Non-root
RUN useradd -r -u 1001 learn && chown -R learn:learn /app
USER learn

ENV PYTHONUNBUFFERED=1 \
    PYTHONDONTWRITEBYTECODE=1 \
    KB_ROOT=/app \
    PORT=8081

EXPOSE 8081

CMD ["python", "-m", "uvicorn", "server:app", "--host", "0.0.0.0", "--port", "8081", "--workers", "1"]
