# syntax=docker/dockerfile:1
FROM docker.io/library/alpine:3.24.2

RUN apk add --no-cache openssh-client tini

COPY --chmod=0755 entrypoint.sh /usr/local/bin/sish-client

# nobody; HOME and state live in /tmp so the root filesystem can be read-only
ENV HOME=/tmp \
    STATE_DIR=/tmp/sish-client
USER 65534:65534

# -g: forward signals to the whole process group, so ssh stops cleanly too
ENTRYPOINT ["/sbin/tini", "-g", "--", "/usr/local/bin/sish-client"]

HEALTHCHECK --interval=15s --timeout=3s --start-period=30s --retries=2 \
  CMD ["/bin/sh", "-c", "test -f \"$STATE_DIR/ready\""]

LABEL org.opencontainers.image.title="sish-client" \
      org.opencontainers.image.description="Environment-driven sish connector (SSH reverse tunnels with SNI passthrough)"
