# Sirius Press — PHP-FPM image with the patched WordPress baked in.
#
# Core comes from this repository's `wordpress/` subtree, not from a download
# and not from the official `wordpress` image. That image ships whatever
# version it was tagged with, and the fork's core patch is pinned to an exact
# one; applying a fork's patch to a different core is how a setup wizard ends
# up half rewritten. Copying the vendored tree makes the image contain exactly
# what `git log wordpress/` describes, with nothing fetched at build time.
#
# Core is staged at /opt/sirius-press/core, not at the document root. The
# entrypoint copies it into place on every start, which is what makes
# `docker compose build --pull && up -d` a real upgrade: the usual layout,
# where the document root is itself a volume, pins core to whatever version
# first created that volume and turns every security release into a manual
# migration.
#
# GMP is installed because the wallet cryptography runs in PHP. Without it the
# fork falls back to BCMath, which works and is roughly twenty times slower —
# unavoidable on a shared host, wasteful in a container we control.

FROM php:8.3-fpm-bookworm

RUN set -eux; \
	apt-get update; \
	apt-get install -y --no-install-recommends \
		ca-certificates curl \
		libfreetype6-dev libjpeg62-turbo-dev libpng-dev libwebp-dev \
		libzip-dev libgmp-dev libicu-dev \
	; \
	docker-php-ext-configure gd --with-freetype --with-jpeg --with-webp; \
	docker-php-ext-install -j"$(nproc)" \
		bcmath gd gmp intl mysqli opcache zip exif \
	; \
	rm -rf /var/lib/apt/lists/*

# Settings a WordPress host wants and the PHP image does not set.
RUN { \
		echo 'upload_max_filesize = 64M'; \
		echo 'post_max_size = 64M'; \
		echo 'memory_limit = 256M'; \
		echo 'max_execution_time = 120'; \
		echo 'opcache.memory_consumption = 128'; \
		echo 'opcache.max_accelerated_files = 10000'; \
		echo 'opcache.revalidate_freq = 2'; \
		echo 'expose_php = Off'; \
	} > /usr/local/etc/php/conf.d/sirius-press.ini

# --- core, from the subtree --------------------------------------------------

COPY wordpress/ /opt/sirius-press/core/

RUN set -eux; \
	test -f /opt/sirius-press/core/wp-includes/version.php; \
	sed -n "s/.*wp_version = '\\(.*\\)'.*/\\1/p" \
		/opt/sirius-press/core/wp-includes/version.php \
		> /opt/sirius-press/core/.sirius-core-version; \
	echo "vendored WordPress $(cat /opt/sirius-press/core/.sirius-core-version)"

# --- the fork -----------------------------------------------------------------
#
# The patch is already applied in the subtree, so there is nothing to patch
# here. patches/ is carried for auditing, not for building.

WORKDIR /opt/sirius-press/core

COPY plugins/ /opt/sirius-press/core/wp-content/plugins/
COPY mu-plugins/ /opt/sirius-press/core/wp-content/mu-plugins/

COPY docker/entrypoint.sh /usr/local/bin/sirius-entrypoint
RUN chmod +x /usr/local/bin/sirius-entrypoint; \
	mkdir -p /var/www/html /var/www/config; \
	chown -R www-data:www-data /var/www/html /var/www/config

WORKDIR /var/www/html

ENTRYPOINT ["sirius-entrypoint"]
CMD ["php-fpm"]
