# mail-admin — read-only web view of the docker-mailserver accounts.
# Build with the Go toolchain, run as a static binary on scratch.
FROM golang:1.25-alpine AS build
WORKDIR /src
COPY go.mod ./
COPY *.go ./
RUN CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o /mail-admin .

FROM scratch
COPY --from=build /mail-admin /mail-admin
# mail-data files are owned by uid/gid 5000 (docker-mailserver), and the
# service mounts ./config and ./data/mail-data read-only.
USER 5000:5000
EXPOSE 8080
ENTRYPOINT ["/mail-admin"]
