# syntax=docker/dockerfile:1
#
# Gitea Actions job-container image for building Rust projects with pixi.
#
# The job never downloads the Rust toolchain: the compiler, C toolchain, and
# pkg-config are baked into pixi's package cache at build time, so `pixi install`
# in a job only links them into the environment instead of fetching them. sccache
# is included so unchanged dependencies are served from a cache instead of being
# recompiled every run.

FROM node:26-trixie-slim@sha256:a1d9d671994fc2d26e297ac56b4b1522a8bc7fa71c43b14cd1b1fe6c5116f7dc

# node is here because Gitea's JavaScript actions (actions/checkout and friends)
# need it. git and ca-certificates are for checkout; curl is for the release API
# calls in the workflows. The C compiler is not installed here: pixi brings it.
RUN apt-get update \
  && apt-get install -y --no-install-recommends \
    git ca-certificates curl \
  && rm -rf /var/lib/apt/lists/*

COPY --from=ghcr.io/prefix-dev/pixi:0.76.1 /usr/local/bin/pixi /usr/local/bin/pixi

# --- Bake the Rust toolchain into pixi's package cache ---
# PIXI_CACHE_DIR is the shared store of downloaded conda packages. Point it at a
# stable path and pre-fill it by installing a throwaway environment that pins the
# same toolchain your projects use. At job time, pixi finds these packages
# already unpacked here and hardlinks them into .pixi/envs with no download. Keep
# RUST_VERSION in step with the projects' pixi.toml; rebuild the image when it
# moves.
ENV PIXI_CACHE_DIR=/opt/pixi/cache
ARG RUST_VERSION=">=1.96.0,<1.97"
RUN <<EOF
set -eux
mkdir -p /opt/pixi/seed
cd /opt/pixi/seed
cat > pixi.toml <<TOML
[workspace]
name = "seed"
version = "0.0.0"
channels = ["conda-forge"]
platforms = ["linux-64"]

[dependencies]
rust = "${RUST_VERSION}"
c-compiler = "*"
pkg-config = "*"
TOML
pixi install
# Keep the warmed cache at /opt/pixi/cache; drop the throwaway environment.
rm -rf /opt/pixi/seed/.pixi
EOF

# --- sccache: cache compiled crates across job runs ---
# The toolchain is baked, but each job still recompiles dependencies unless the
# output is cached. sccache stores compiled artifacts keyed by their inputs, so
# unchanged crates are copied from cache instead of rebuilt. This only helps if
# SCCACHE_DIR and CARGO_HOME persist between jobs, which the named volumes below
# provide.
ARG SCCACHE_VERSION=0.17.0
ARG SCCACHE_SHA256=67c4a96dd237c1f518f6b36083f270f9976d516f1e57fce891755ea782e50006
RUN <<EOF
set -eux
cd /tmp
asset="sccache-v${SCCACHE_VERSION}-x86_64-unknown-linux-musl"
curl -fsSLO "https://github.com/mozilla/sccache/releases/download/v${SCCACHE_VERSION}/${asset}.tar.gz"
echo "${SCCACHE_SHA256}  ${asset}.tar.gz" | sha256sum -c -
tar -xzf "${asset}.tar.gz"
install -m 0755 "${asset}/sccache" /usr/local/bin/sccache
rm -rf "${asset}" "${asset}.tar.gz"
EOF

ENV CARGO_HOME=/opt/cargo \
    SCCACHE_DIR=/opt/sccache \
    SCCACHE_CACHE_SIZE=2G \
    RUSTC_WRAPPER=sccache \
    CARGO_INCREMENTAL=0
RUN mkdir -p /opt/cargo /opt/sccache
