FROM python:3.13-slim

# Non-root user for security
RUN useradd --system --create-home --home-dir /app checkpoint

WORKDIR /app

# Dependencies first (layer caching — reinstall only when requirements change)
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt

# App code
COPY . .

# instance/ is a Docker volume — just ensure the directory exists with right owner
RUN mkdir -p instance/uploads && chown -R checkpoint:checkpoint /app

USER checkpoint

EXPOSE 8000

CMD ["gunicorn", "-c", "gunicorn.conf.py", "wsgi:app"]