FROM debian:13-slim AS build

ARG DEBIAN_FRONTEND=noninteractive
ARG LLAMA_CPP_COMMIT
RUN apt-get update && apt-get install -y --no-install-recommends \
    build-essential ca-certificates cmake git libcurl4-openssl-dev libopenblas-dev \
    ninja-build pkg-config && \
    rm -rf /var/lib/apt/lists/*
RUN test -n "$LLAMA_CPP_COMMIT"
RUN git clone --filter=blob:none https://github.com/ggml-org/llama.cpp /src/llama.cpp && \
    git -C /src/llama.cpp checkout "$LLAMA_CPP_COMMIT"
RUN cmake -S /src/llama.cpp -B /src/llama.cpp/build -G Ninja \
    -DCMAKE_BUILD_TYPE=Release \
    -DGGML_NATIVE=ON \
    -DGGML_BLAS=ON \
    -DGGML_BLAS_VENDOR=OpenBLAS && \
    cmake --build /src/llama.cpp/build --target llama-server -j "$(nproc)"

FROM debian:13-slim
ARG DEBIAN_FRONTEND=noninteractive
ARG LLAMA_CPP_COMMIT
RUN apt-get update && apt-get install -y --no-install-recommends \
    ca-certificates curl libcurl4 libgomp1 libopenblas0-pthread python3 && \
    rm -rf /var/lib/apt/lists/* && \
    useradd --system --uid 10003 --home /nonexistent --shell /usr/sbin/nologin llama
COPY --from=build /src/llama.cpp/build/bin/ /opt/llama/bin/
LABEL org.opencontainers.image.source="https://github.com/ggml-org/llama.cpp" \
      com.mike-ai.llama-cpp-commit="$LLAMA_CPP_COMMIT" \
      com.mike-ai.llama-cpp-backend="cpu-openblas"
ENV LD_LIBRARY_PATH=/opt/llama/bin
USER 10003:10003
ENTRYPOINT ["/opt/llama/bin/llama-server"]
