# build.sh produces the binary this packages. It is statically linked and carries
# the page inside it, so there is nothing to compile or install here.
FROM alpine:latest

# Alpine ships no CA bundle, and a Go binary reads the system one: without this
# every token exchange fails verifying the provider's certificate.
RUN apk --no-cache add ca-certificates

WORKDIR /app
COPY auther-linux-amd64 ./auther

# The database is put somewhere a volume can be mounted, because the container
# holds every credential and a lost one means authorizing every account again.
ENV AUTHER_DB=/data/auther.db
VOLUME /data

EXPOSE 8080
CMD ["./auther"]
