# n8n with what its workflows reach for beyond the upstream image.
#
# The base is named, not pinned here (novox/hq issue 044): module.json's `build.on` declares N8N_BASE
# as the upstream image by digest, and the mesh hands the build its own copy (ADR 0097).
ARG N8N_BASE
FROM ${N8N_BASE}

USER root
# - `media` (GID 2000), with `node` in it: the shared media library is group-writable by the
#   operator's media group, and a workflow files downloads into it. A container resource cannot add
#   a supplementary group, so the image's own /etc/group carries it. 2000 is the operator's media
#   group today; novox/hq 153 proposes reading it from the accessed data (${access:<id>:gid}).
# - uuid, pinned to the version the workflows were written against: Code nodes require() it
#   (NODE_FUNCTION_ALLOW_EXTERNAL=*), and a Code node can only require what is installed.
RUN apk add --no-cache shadow \
 && groupadd -g 2000 media \
 && usermod -aG media node \
 && npm install -g uuid@14.0.1

USER node
