# rein-aharness — shared unattended agent runtime (Railiance / local).
# Build: docker build -f Containerfile -t rein-aharness:local .
# Optional llm-connect sibling: docker build --build-arg WITH_LLM_CONNECT=1 ...
FROM python:3.12-slim

ENV PYTHONDONTWRITEBYTECODE=1 \
    PYTHONUNBUFFERED=1 \
    PATH="/home/harness/.local/bin:$PATH" \
    STATE_HUB_URL=http://state-hub.state-hub.svc.cluster.local:8000

WORKDIR /app

RUN apt-get update \
    && apt-get install -y --no-install-recommends git openssh-client ca-certificates \
    && rm -rf /var/lib/apt/lists/* \
    && groupadd -g 10001 harness \
    && useradd -u 10001 -g 10001 -m -s /usr/sbin/nologin harness

COPY pyproject.toml README.md ./
COPY rein_aharness ./rein_aharness
# Populated by `make image` from ../llm-connect when present.
COPY llm_connect_vendor ./llm_connect_vendor

RUN pip install --no-cache-dir "httpx>=0.27" "PyYAML>=6.0" \
    && pip install --no-cache-dir --no-deps . \
    && if [ -f llm_connect_vendor/pyproject.toml ]; then \
         pip install --no-cache-dir ./llm_connect_vendor; \
       fi \
    && rm -rf /root/.cache/pip

USER 10001:10001

# No long-running HTTP API yet — image is invoked as CLI (run / smoke / validate).
ENTRYPOINT ["rein-aharness"]
CMD ["profiles"]
