# syntax=docker/dockerfile:1

# ── Stage 1: Build Python agent deps with uv ───────────────────────────────
FROM ghcr.io/astral-sh/uv:python3.12-bookworm-slim AS build

ENV PYTHONUNBUFFERED=1
ENV UV_COMPILE_BYTECODE=1

WORKDIR /app

# Install build tools for native extensions (azure-cognitiveservices-speech)
RUN apt-get update && apt-get install -y --no-install-recommends \
    gcc g++ python3-dev libasound2-dev \
    && rm -rf /var/lib/apt/lists/*

COPY agent/pyproject.toml ./agent/
RUN cd /app/agent && \
    uv venv .venv && \
    uv pip install --python .venv/bin/python \
        "livekit-agents[mcp]~=1.7" \
        "livekit-plugins-azure~=1.7" \
        "livekit-plugins-openai~=1.7" \
        "python-dotenv"

# ── Stage 2: Runtime (use same base for Python compat) ─────────────────────
FROM ghcr.io/astral-sh/uv:python3.12-bookworm-slim AS runtime

ENV PYTHONUNBUFFERED=1
# Fix SSL cert path for the slim base image (ca-certificates installs to /etc/ssl/certs)
ENV SSL_CERT_FILE=/etc/ssl/certs/ca-certificates.crt

# Install LiveKit server binary + supervisord + nginx
RUN apt-get update && apt-get install -y --no-install-recommends \
    curl ca-certificates supervisor nginx libasound2 iproute2 \
    && rm -rf /var/lib/apt/lists/*

# Download LiveKit server (latest stable)
ARG LIVEKIT_VERSION=v1.13.5
ARG LIVEKIT_TAG=1.13.5
RUN curl -sSL "https://github.com/livekit/livekit/releases/download/${LIVEKIT_VERSION}/livekit_${LIVEKIT_TAG}_linux_amd64.tar.gz" \
    | tar xz -C /usr/local/bin/ livekit-server \
    && chmod +x /usr/local/bin/livekit-server \
    && ln -sf /usr/local/bin/livekit-server /usr/local/bin/livekit

# Copy Python agent + venv from build stage
COPY --from=build /app/agent/.venv /opt/voice-agent/.venv
COPY agent/agent.py /opt/voice-agent/agent.py
COPY agent/web_mcp.py /opt/voice-agent/web_mcp.py

# Copy web frontend + token endpoint
COPY web/ /var/www/voice/
COPY web/token_server.py /opt/voice/token_server.py

# Config files
COPY livekit.yaml /etc/livekit.yaml
COPY supervisord.conf /etc/supervisor/conf.d/voice.conf

# Configure nginx to serve the voice UI on port 8090 over HTTPS.
# Browsers require a secure context (HTTPS or localhost) for microphone access.
# The self-signed cert (with the LAN IP in the SAN) is generated at container
# start by entrypoint.sh.
RUN rm -f /etc/nginx/sites-enabled/default \
    && mkdir -p /etc/voice/certs \
    && printf 'server {\n    listen 8090 ssl;\n    root /var/www/voice;\n    index index.html;\n    ssl_certificate /etc/voice/certs/cert.pem;\n    ssl_certificate_key /etc/voice/certs/key.pem;\n    location /token {\n        proxy_pass http://127.0.0.1:8091/token;\n        proxy_set_header Content-Type application/json;\n    }\n    location = /livekit {\n        return 301 /livekit/;\n    }\n    location /livekit/ {\n        proxy_pass http://127.0.0.1:7880/;\n        proxy_http_version 1.1;\n        proxy_set_header Upgrade $http_upgrade;\n        proxy_set_header Connection "upgrade";\n        proxy_set_header Host $host;\n        proxy_read_timeout 3600s;\n        proxy_send_timeout 3600s;\n    }\n    location / {\n        try_files $uri $uri/ =404;\n    }\n}\n' \
    > /etc/nginx/sites-available/voice \
    && ln -sf /etc/nginx/sites-available/voice /etc/nginx/sites-enabled/voice

# Create non-root user for agent
RUN useradd -m -s /bin/bash voiceuser || true

COPY entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh

EXPOSE 7880 7881 7882/udp 8090

ENTRYPOINT ["/entrypoint.sh"]
CMD ["supervisord", "-n", "-c", "/etc/supervisor/conf.d/voice.conf"]
