# Hugo static-site build image. The build runs `make check` (the
# read-only prettier docs check plus a clean `hugo --minify` production
# build), so the image build fails on any formatting or Hugo build
# error. This is what CI (script/cibuild) runs on every push.
# alpine 3.21, 2026-02-28
FROM alpine@sha256:c3f8e73fdb79deaebaa2037150150191b9dcbfba68b4a46d70103204c53f4709

WORKDIR /src

# Install build dependencies first so the layer caches until the
# scripts change (script/bootstrap installs git, make, hugo, node/npm).
COPY script/ script/
RUN script/bootstrap

COPY . .

# Run all checks - build fails if any check fails.
RUN make check
