ARG WMS_BASE_IMAGE="harbor.cta-observatory.org/dpps/wms-base:dev"
FROM ${WMS_BASE_IMAGE}

ARG USERID=1000
ARG GROUPID=1000

ENV DIRAC_DIR=/opt/dirac

RUN dnf install -y procps-ng psmisc openssh-clients iptables-services unzip bzip2 git \
  && dnf clean all -y \
  && \
  if getent group ${GROUPID}; then \
    groupmod --new-name dirac $(getent group ${GROUPID} | cut -d: -f1); \
  else \
    groupadd --gid ${GROUPID} dirac; \
  fi\
  && adduser --uid ${USERID} --gid dirac -s /bin/bash -d /home/dirac dirac \
  && mkdir -p /etc/grid-security/certificates && chmod -R o+r /etc/grid-security/ \
  && mkdir -p ${DIRAC_DIR} \
  && chown -R dirac:dirac ${DIRAC_DIR}

# SSHComputingElement creates control_script.py in BatchSystems at runtime.
RUN micromamba install -y -p "${DIRACOS}" \
    -c conda-forge -c diracgrid \
    'diracx-db<0.2.0' \
    'mysqlclient >=2.0.3,<2.1' 'mysql-client' 'python-gfal2>1.13.0' \
    'tornado_m2crypto>0.1.3' \
  && "${DIRACOS}/bin/pip" install --no-cache-dir \
    "CTADIRAC[server]==${CTADIRAC_VERSION}" \
  && micromamba clean -a -y \
  && chown dirac:dirac \
    "${DIRACOS}/lib/python3.12/site-packages/DIRAC/Resources/Computing/BatchSystems"

COPY --chown=dirac:dirac --chmod=755 Entrypoint.sh /Entrypoint.sh

# run everything here as dirac user to get correct permissions
USER dirac

WORKDIR /opt/dirac

RUN mkdir -p /opt/dirac/etc/grid-security/certificates \
  && mkdir -p /home/dirac/.ssh /home/dirac/.globus

COPY --chown=dirac:dirac --chmod=755 ./configure.py ./delete_section.py /home/dirac/
COPY --chown=dirac:dirac --chmod=755 bashrc /opt/dirac/

ENV DIRAC_ROOT_PATH="${DIRAC_DIR}"

ENTRYPOINT ["/Entrypoint.sh"]
