# The bucket provisioner, as a module ships one.
#
# Built here so a machine can be given it by the mesh rather than by somebody putting a binary on
# it.
#
# **Not FROM scratch, unlike the postgres one, and the difference is the point.** This drives the
# store's own command line, so that client has to be in the image — a provisioner is allowed to
# know how to operate the thing it provisions.
#
# The client is copied from the vendor's own image rather than installed from a distribution:
# `apk add mc` on Alpine installs Midnight Commander, which is a different program with the same
# name, and the failure would be a provisioner that starts cleanly and cannot do anything.
FROM golang:1.25-alpine AS build
WORKDIR /src
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 go build -trimpath -ldflags '-s -w' \
    -o /mesh-provision-objectstore ./examples/objectstore-provisioner

# Pinned like everything else the mesh runs (novox/hq ADR 0006): a tag moves and a digest does not.
FROM minio/mc:latest AS client

FROM alpine:3.21
RUN apk add --no-cache ca-certificates
COPY --from=client /usr/bin/mc /usr/bin/mc
COPY --from=build /mesh-provision-objectstore /mesh-provision-objectstore
# Watching by default, because that is what makes it a module: an ordinary long-running service
# the host supervises, rather than something invoked after every declaration.
ENTRYPOINT ["/mesh-provision-objectstore", "--watch"]
