# python:3.14-slim from Docker Hub, pinned to the index digest the tag pointed to on 2026-09-28.
# The tag moves on every rebuild; the digest names these exact bytes for every architecture.
FROM docker.io/library/python:3.14-slim@sha256:51dafde81dbdb6ebde285137a295cf18a47ca95234fe388a343719cb97305b3d

# The account the tool runs as: no login shell, no home, not root.
RUN useradd --uid 10001 --no-create-home --shell /usr/sbin/nologin certcheck

# Dependencies from the hash lock: a file whose SHA-256 is not in the lock fails the build.
# The venv gets no pip of its own; the base image's pip installs into it (--python), so the
# runtime environment holds only the tool and what it needs.
COPY requirements.txt /tmp/requirements.txt
RUN python -m venv --without-pip /opt/certcheck \
    && python -m pip --python /opt/certcheck/bin/python install --no-cache-dir \
       --disable-pip-version-check --require-hashes -r /tmp/requirements.txt

# Then the tool's own wheel, with nothing else resolved.
COPY dist/certcheck-0.1.0-py3-none-any.whl /tmp/
RUN python -m pip --python /opt/certcheck/bin/python install --no-cache-dir \
       --disable-pip-version-check --no-deps /tmp/certcheck-0.1.0-py3-none-any.whl \
    && rm /tmp/certcheck-0.1.0-py3-none-any.whl /tmp/requirements.txt

USER 10001
ENTRYPOINT ["/opt/certcheck/bin/certcheck"]
