# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at http://mozilla.org/MPL/2.0/.

FROM ubuntu:24.04

# refresh repos otherwise installations later may fail
# install engine run-time dependencies
# install adduser, findutils, openssl and cpio that we need later
# install tzdata to accept the TZ environment variable
# install an editor
# tdf#117557 - Add CJK Fonts to Collabora Online Docker Image
RUN apt-get update && \
    apt-get -y install libpng16-16 fontconfig adduser cpio tzdata \
               findutils nano \
               libcap2-bin openssl openssh-client \
               libxcb-shm0 libxcb-render0 libxrender1 libxext6 \
               fonts-wqy-zenhei fonts-wqy-microhei fonts-droid-fallback \
               fonts-noto-cjk ca-certificates

# copy freshly built engine and Collabora Online
COPY /instdir /

# set up Collabora Online (normally done by postinstall script of package)
# Fix permissions
RUN setcap cap_fowner,cap_chown,cap_sys_chroot=ep /usr/bin/coolforkit-caps && \
    setcap cap_sys_admin=ep /usr/bin/coolmount && \
    adduser --quiet --system --group --home /opt/cool cool && \
    rm -rf /opt/cool && \
    mkdir -p /opt/cool/child-roots /opt/cool/cache && \
    coolwsd-systemplate-setup /opt/cool/systemplate /opt/collaboraoffice >/dev/null 2>&1 && \
    touch /var/log/coolwsd.log && \
    chown cool:cool /var/log/coolwsd.log && \
    chown -R cool:cool /opt/ && \
    chown -R cool:cool /etc/coolwsd && \
    # coolwsd appends a mapping for an arbitrary (e.g. OpenShift) UID to
    # /etc/passwd at startup, so it must be writable by the root group
    chmod g+w /etc/passwd

EXPOSE 9980

# switch to cool user (use numeric user id to be compatible with Kubernetes Pod Security Policies)
USER 100

# Start coolwsd directly, with no shell in between: self-signed certificate
# generation (unless DONT_GEN_SSL_CERT is set) and arbitrary-UID handling are
# done inside coolwsd itself. The configuration is still driven dynamically by
# environment variables (--use-env-vars).
ENTRYPOINT ["/usr/bin/coolwsd", \
            "--use-env-vars", \
            "--o:sys_template_path=/opt/cool/systemplate", \
            "--o:child_root_path=/opt/cool/child-roots", \
            "--o:file_server_root_path=/usr/share/coolwsd", \
            "--o:cache_files.path=/opt/cool/cache", \
            "--o:logging.color=false", \
            "--o:stop_on_config_change=true"]
