# The signer: the container that talks to the HSM, started beside the action's own
# container by entrypoint.sh. See hsm-sign.sh for what it does.
#
# Debian with opensc, reaching the HSM through the host's pcscd socket (mounted at run
# time) as an unprivileged uid 1000. Plus Debian's apksigner, which signs APKs through
# Java's SunPKCS11 provider and so needs nothing but opensc's PKCS#11 module, and
# OpenSSL's PKCS#11 engine, used once to make the certificate an APK signature has to
# carry (hsm-sign.sh, make-cert).
#
# The action builds this on the host's docker daemon at run time, so the image always
# matches the action's version, and the layers are cached there between runs. opensc
# and pcsc-lite have to speak the host pcscd's socket protocol, so this follows the
# host's Debian release (nas2: bookworm). That is the one thing here test.sh cannot show:
# it uses SoftHSM, with no pcscd.
#
# BASE is an argument so the image can follow the host if it moves.
ARG BASE=debian:bookworm
FROM ${BASE}

RUN apt-get update && \
    apt-get install -y --no-install-recommends \
      opensc openjdk-17-jre-headless libapksig-java openssl libengine-pkcs11-openssl ca-certificates && \
    # Debian's apksigner package depends on the desktop JRE (default-jre: AWT, GTK, Mesa,
    # X11, icon themes - 115 packages instead of 42) though it is a command-line tool that
    # runs on the headless one. So its files are unpacked rather than the package
    # installed: one jar and its wrapper script, and the headless JRE and libapksig it
    # needs are installed above. dpkg's database never hears of it, so there is no
    # broken dependency left for a later apt-get to trip on.
    cd /tmp && apt-get download apksigner && dpkg-deb -x apksigner_*.deb / && rm apksigner_*.deb && \
    useradd -m -u 1000 user && \
    rm -rf /var/lib/apt/lists/*

COPY hsm-sign.sh /usr/local/bin/hsm-sign

USER user
WORKDIR /home/user
ENTRYPOINT ["/usr/local/bin/hsm-sign"]
