# Trading Portal — Optimized Backend Dockerfile
# python:3.13-alpine base + single RUN layer for build deps → runtime

FROM python:3.13-alpine

WORKDIR /app

# ── Single RUN: install build deps → pip install → purge build deps ──
# This keeps ONLY the final state in ONE layer (~saves 250MB vs separate layers)
RUN apk add --no-cache --virtual .build-deps \
        gcc g++ musl-dev python3-dev libffi-dev openssl-dev cargo \
    && pip install --no-cache-dir \
        fastapi==0.115.0 \
        "uvicorn[standard]==0.30.0" \
        "sqlalchemy[asyncio]==2.0.35" \
        asyncpg==0.30.0 \
        alembic==1.13.0 \
        pydantic==2.9.0 \
        pydantic-settings==2.5.0 \
        "python-jose[cryptography]==3.3.0" \
        "passlib[bcrypt]==1.7.4" \
        bcrypt==4.0.1 \
        "ccxt>=4.3" \
        apscheduler==3.10.4 \
        cachetools==5.5.0 \
        structlog==24.4.0 \
        httpx==0.27.0 \
        websockets==13.0 \
        python-multipart==0.0.12 \
        cryptography==43.0.0 \
        redis==8.0.1 \
    && apk del .build-deps \
    && rm -rf /root/.cache /tmp/* /var/cache/apk/*

# ── Copy app code ──
COPY app/ ./app/
COPY scripts/ ./scripts/

# ── Clean pycache ──
RUN find /app -type d -name __pycache__ -exec rm -rf {} + 2>/dev/null; \
    find /app -type f -name "*.pyc" -delete 2>/dev/null; \
    exit 0

# Healthcheck defined per-service in docker-compose.yml

CMD ["uvicorn", "app.main:app", "--host", "0.0.0.0", "--port", "8001", "--proxy-headers", "--forwarded-allow-ips", "*"]
