ARG AWS_CLI_VERSION=2.36.2
# Pinned to the last 28.x. The original TLS 1.3 panic that pinned this
# (msft-golang golang-fips/openssl, commit 9470aa06) IS fixed in 29.x
# (golang-fips/openssl #417,#418) — but Docker 29.x breaks minikube-in-docker:
# kicbase fails its nested overlay mount (fstype: overlay, invalid argument),
# which reproducibly fails the e2e job. 28.5.2 is unaffected by both issues.
ARG DOCKER_VERSION=28.5.2
ARG NODE_VERSION=22
ARG OPENTOFU_VERSION=1.12.4
ARG PYTHON_VERSION=3.13
ARG TFLINT_VERSION=0.64.0
ARG UV_VERSION=0.12.3

FROM amazon/aws-cli:${AWS_CLI_VERSION} AS aws-cli
FROM ghcr.io/astral-sh/uv:${UV_VERSION} AS uv
FROM ghcr.io/opentofu/opentofu:${OPENTOFU_VERSION}-minimal AS opentofu
FROM ghcr.io/terraform-linters/tflint:v${TFLINT_VERSION} AS tflint
FROM node:${NODE_VERSION}-bookworm AS node
FROM rancher/kubectl:v1.36.2 AS kubectl

FROM alpine:3.24 AS helm
ARG TARGETARCH
ARG HELM_VERSION=4.2.3
# Retry with backoff, and never pipe curl into tar: a mid-body drop (curl 56) can't
# be retried once partial bytes have hit the pipe. Download to a file, then extract.
RUN apk add --no-cache curl \
 && printf 'retry = 5\nretry-delay = 3\nretry-all-errors\n' > /root/.curlrc \
 && curl -fsSL -o /tmp/helm.tgz https://get.helm.sh/helm-v${HELM_VERSION}-linux-${TARGETARCH}.tar.gz \
 && tar -zxf /tmp/helm.tgz \
 && mv linux-${TARGETARCH}/helm /helm \
 && rm /tmp/helm.tgz

FROM python:${PYTHON_VERSION}-bookworm

# Transient CDN drops (curl 56) were killing the build; retry with backoff on every
# curl in this stage, and download to files instead of piping (a retry can't rewind
# bytes already written into a pipe).
RUN printf 'retry = 5\nretry-delay = 3\nretry-all-errors\n' > /root/.curlrc

ARG TARGETARCH
ARG APP_USER=metr
ARG APP_DIR=/home/${APP_USER}/app
ARG USER_ID=1000
ARG GROUP_ID=1000

RUN groupadd -g ${GROUP_ID} ${APP_USER} \
 && useradd -m -u ${USER_ID} -g ${APP_USER} -s /bin/bash ${APP_USER} \
 && mkdir -p \
        /home/${APP_USER}/.aws \
        /home/${APP_USER}/.kube \
        ${APP_DIR} \
 && chown -R ${USER_ID}:${GROUP_ID} \
        /home/${APP_USER} \
        ${APP_DIR}

RUN --mount=type=cache,target=/var/lib/apt/lists,sharing=locked \
    --mount=type=cache,target=/var/cache/apt,sharing=locked \
    apt-get update \
 && apt-get install -y --no-install-recommends \
        bash-completion \
        curl \
        dnsutils \
        gh \
        git-lfs \
        groff \
        inetutils-ping \
        jq \
        less \
        locales \
        lsof \
        man \
        nano \
        openssh-client \
        postgresql-client \
        rsync \
        skopeo \
        unzip \
        vim \
        wget \
        zip \
        zsh \
 && sed -i -e 's/# en_US.UTF-8 UTF-8/en_US.UTF-8 UTF-8/' /etc/locale.gen \
 && locale-gen en_US.UTF-8 \
 && git lfs install

ENV LANG=en_US.UTF-8
ENV LANGUAGE=en_US:en
ENV LC_ALL=en_US.UTF-8

ARG DOCKER_VERSION
ARG DOCKER_COMPOSE_VERSION=5.3.1
ARG DOCKER_GID=999
ENV DOCKER_BUILDKIT=1
ARG DEVCONTAINERS_VERSION=765e8ebd8f8012fb740cd7b41483a745bcedd212
RUN --mount=type=cache,target=/var/lib/apt/lists,sharing=locked \
    --mount=type=cache,target=/var/cache/apt,sharing=locked \
    apt-get update \
 && curl -fsSL -o /tmp/dind-install.sh https://raw.githubusercontent.com/devcontainers/features/${DEVCONTAINERS_VERSION}/src/docker-in-docker/install.sh \
# INSTALLDOCKERBUILDX=false: buildx is already installed via apt (moby-buildx). The
# feature's standalone download resolves "latest" against git tags, not releases, so a
# freshly-cut buildx tag with no published binary (e.g. v0.35.0) 404s and breaks the build.
 && VERSION=${DOCKER_VERSION} DOCKERDASHCOMPOSEVERSION=${DOCKER_COMPOSE_VERSION} INSTALLDOCKERBUILDX=false bash /tmp/dind-install.sh \
 && rm /tmp/dind-install.sh \
 && apt-get update \
 && groupmod -g ${DOCKER_GID} docker \
 && usermod -aG docker ${APP_USER}

ARG GVISOR_VERSION=20260714.0
RUN ARCH=$([ "$TARGETARCH" = "arm64" ] && echo aarch64 || echo x86_64) \
 && URL=https://storage.googleapis.com/gvisor/releases/release/${GVISOR_VERSION}/${ARCH} \
 && wget \
        ${URL}/containerd-shim-runsc-v1 \
        ${URL}/containerd-shim-runsc-v1.sha512 \
        ${URL}/runsc \
        ${URL}/runsc.sha512 \
 && sha512sum -c runsc.sha512 -c containerd-shim-runsc-v1.sha512 \
 && rm -f *.sha512 \
 && chmod a+rx runsc containerd-shim-runsc-v1 \
 && mv runsc containerd-shim-runsc-v1 /usr/local/bin \
 && mkdir -p /etc/docker \
 && cat <<EOF > /etc/docker/daemon.json
{
    "runtimes": {
        "runsc": {
            "path": "/usr/local/bin/runsc"
        }
    }
}
EOF

ARG MINIKUBE_VERSION=1.38.1
RUN curl -fsSLo ./minikube https://github.com/kubernetes/minikube/releases/download/v${MINIKUBE_VERSION}/minikube-linux-${TARGETARCH} \
 && install -m 755 minikube /usr/local/bin/minikube

ARG CILIUM_CLI_VERSION=0.19.6
RUN curl -fsSL -o /tmp/cilium.tgz https://github.com/cilium/cilium-cli/releases/download/v${CILIUM_CLI_VERSION}/cilium-linux-${TARGETARCH}.tar.gz \
 && tar -zxf /tmp/cilium.tgz cilium \
 && install -m 755 cilium /usr/local/bin/cilium \
 && rm /tmp/cilium.tgz cilium

ARG K9S_VERSION=0.51.0
RUN curl -fsSL -o /tmp/k9s.tgz https://github.com/derailed/k9s/releases/download/v${K9S_VERSION}/k9s_Linux_${TARGETARCH}.tar.gz \
 && tar -xzf /tmp/k9s.tgz k9s \
 && install -m 755 k9s /usr/local/bin/k9s \
 && rm /tmp/k9s.tgz k9s

ARG PUP_VERSION=1.6.5
RUN PUP_ARCH=$([ "$TARGETARCH" = "arm64" ] && echo arm64 || echo x86_64) \
 && curl -fsSL -o /tmp/pup.tgz https://github.com/DataDog/pup/releases/download/v${PUP_VERSION}/pup_${PUP_VERSION}_Linux_${PUP_ARCH}.tar.gz \
 && tar -xzf /tmp/pup.tgz pup \
 && install -m 755 pup /usr/local/bin/pup \
 && rm /tmp/pup.tgz pup

ARG PULUMI_VERSION=3.253.0
RUN PULUMI_ARCH=$([ "$TARGETARCH" = "arm64" ] && echo arm64 || echo x64) \
 && mkdir -p /tmp/pulumi \
 && curl -fsSL -o /tmp/pulumi.tgz https://get.pulumi.com/releases/sdk/pulumi-v${PULUMI_VERSION}-linux-${PULUMI_ARCH}.tar.gz \
 && tar -xz -C /tmp/pulumi --strip-components=1 -f /tmp/pulumi.tgz \
 && install -m 755 /tmp/pulumi/pulumi* /usr/local/bin/ \
 && rm -rf /tmp/pulumi /tmp/pulumi.tgz

COPY --from=aws-cli /usr/local/aws-cli/v2/current /usr/local
COPY --from=helm /helm /usr/local/bin/helm
COPY --from=kubectl /bin/kubectl /usr/local/bin/
COPY --from=node /usr/local/bin /usr/local/bin
COPY --from=node /usr/local/lib/node_modules /usr/local/lib/node_modules
COPY --from=opentofu --link /usr/local/bin/tofu /usr/local/bin/tofu
COPY --from=tflint /usr/local/bin/tflint /usr/local/bin/tflint
COPY --from=uv /uv /uvx /usr/local/bin/

ARG PNPM_VERSION=10.34.5
RUN --mount=type=cache,target=/root/.npm \
    npm install --global --force pnpm@${PNPM_VERSION}

ARG DOCKER_ECR_HELPER=0.12.0
RUN curl -fsSL \
        https://amazon-ecr-credential-helper-releases.s3.us-east-2.amazonaws.com/${DOCKER_ECR_HELPER}/linux-${TARGETARCH}/docker-credential-ecr-login \
    -o /usr/local/bin/docker-credential-ecr-login \
 && chmod +x /usr/local/bin/docker-credential-ecr-login

# ECR registries the devcontainer authenticates against, as a space-separated
# list of AWS account IDs. Empty in the repo so org-specific IDs stay out of
# it; real values come from the devcontainer build arg, which reads your local
# ECR_ACCOUNT_IDS env var.
ARG ECR_ACCOUNT_IDS=""
RUN mkdir -p /home/${APP_USER}/.docker \
 && { \
      printf '{\n  "credHelpers": {'; \
      sep=""; \
      for id in ${ECR_ACCOUNT_IDS}; do \
        printf '%s\n    "%s.dkr.ecr.us-west-2.amazonaws.com": "ecr-login"' "$sep" "$id"; \
        sep=","; \
      done; \
      printf '\n  }\n}\n'; \
    } > /home/${APP_USER}/.docker/config.json \
 && chown -R ${USER_ID}:${GROUP_ID} /home/${APP_USER}/.docker

RUN echo 'eval "$(uv generate-shell-completion bash)"' >> /etc/bash_completion.d/uv \
 && echo "complete -C '/usr/local/bin/tofu' terraform" >> /etc/bash_completion.d/terraform \
 && echo "complete -C '/usr/local/bin/tofu' tofu" >> /etc/bash_completion.d/tofu \
 && echo "complete -C '/usr/local/bin/aws_completer' aws" >> /etc/bash_completion.d/aws \
 && docker completion bash > /etc/bash_completion.d/docker \
 && cilium completion bash > /etc/bash_completion.d/cilium \
 && helm completion bash > /etc/bash_completion.d/helm \
 && kubectl completion bash > /etc/bash_completion.d/kubectl \
 && minikube completion bash > /etc/bash_completion.d/minikube \
 && pulumi gen-completion bash > /etc/bash_completion.d/pulumi \
 && ln -s /usr/local/bin/tofu /usr/local/bin/terraform

WORKDIR ${APP_DIR}

ENTRYPOINT ["/usr/local/share/docker-init.sh"]
CMD ["sleep", "infinity"]
