ARG WMS_BASE_IMAGE="harbor.cta-observatory.org/dpps/wms-base:dev"
FROM ${WMS_BASE_IMAGE}

ARG USERID=1000
ARG GROUPID=1000

ENV DIRAC_DIR=/home/dirac

RUN \
  dnf install -y epel-release https://cvmrepo.s3.cern.ch/cvmrepo/yum/cvmfs-release-latest.noarch.rpm \
  && dnf install -y apptainer nodejs cvmfs inotify-tools openssh-clients openssh-server bzip2 git \
  && dnf clean all -y \
  && cvmfs_config setup \
  && cd /etc/ssh && ssh-keygen -A

COPY default.local /etc/cvmfs/default.local
COPY sw.ctao.dpps.test.conf containers.ctao.dpps.test.conf /etc/cvmfs/config.d/
COPY --chmod=600 --chown=root:root 100-sshd_only_public_key_auth.conf /etc/ssh/sshd_config.d/100-sshd_only_public_key_auth.conf

RUN micromamba install -y -p "${DIRACOS}" \
    -c conda-forge -c diracgrid \
    'mysqlclient >=2.0.3,<2.1' \
  && "${DIRACOS}/bin/pip" install --no-cache-dir \
    "CTADIRAC[pilot]==${CTADIRAC_VERSION}" \
  && micromamba clean -a -y

RUN mkdir -p /etc/grid-security/certificates /etc/grid-security/vomsdir/ctao.dpps.test /etc/grid-security/vomses \
  && touch /etc/grid-security/vomses/ctao.dpps.test \
  && if getent group ${GROUPID}; then \
    groupmod --new-name dirac $(getent group ${GROUPID} | cut -d: -f1); \
  else \
    groupadd --gid ${GROUPID} dirac;\
  fi \
  && adduser --uid ${USERID} --gid dirac -s /bin/bash -d /home/dirac dirac \
  && mkdir -p /home/dirac/.ssh /home/dirac/data && chown -R dirac:dirac /home/dirac

COPY Entrypoint.sh /Entrypoint.sh
CMD ["/Entrypoint.sh"]
