# Cowork Linux Worker for hosts without a WireGuard kernel module (Synology DSM 7,
# kernel 4.4). The image carries only OS tools; the signed release and its Node
# runtime live in the service volume and follow the regular signed update channel.
FROM golang:1.22-bookworm AS wireguard-go
ARG WIREGUARD_GO_VERSION=0.0.20230223
RUN git clone --depth 1 --branch "${WIREGUARD_GO_VERSION}" https://git.zx2c4.com/wireguard-go /src \
  && cd /src && CGO_ENABLED=0 go build -trimpath -ldflags "-s -w" -o /wireguard-go .

FROM ubuntu:24.04
ARG DEBIAN_FRONTEND=noninteractive
# wg-quick falls back to wireguard-go when `ip link add ... type wireguard` fails.
RUN apt-get update \
  && apt-get install -y --no-install-recommends ca-certificates wireguard-tools iproute2 python3 procps \
     util-linux tini mawk \
  && rm -rf /var/lib/apt/lists/*
COPY --from=wireguard-go /wireguard-go /usr/bin/wireguard-go
# Fixed UID so the account survives container re-creation; the installer accepts an
# existing system account with exactly this home and shell.
RUN useradd --system --user-group --uid 990 --home-dir /var/lib/cowork-worker --shell /usr/sbin/nologin cowork
COPY deploy/linux-worker-container/entrypoint.sh /usr/local/sbin/cowork-worker-entrypoint
RUN chmod 0755 /usr/local/sbin/cowork-worker-entrypoint
ENTRYPOINT ["/usr/bin/tini", "--", "/usr/local/sbin/cowork-worker-entrypoint"]
