# A machine that has never seen this project: Debian, PostgreSQL from the PostgreSQL
# project's own apt repository, a stranger's toolchain, and the repository as git has it.
# Everything the verification needs is installed here, from where anyone gets it, and
# nothing comes from the machine that wrote the code. Built by tests/clean-machine/run.sh,
# which is also what CI runs (.github/workflows/verify.yml) -- one definition of
# "verified", not two that can drift.
#
# PG_MAJOR picks the version. PGDG publishes each major in its own component, betas
# included, so 19 resolves to the newest 19 beta without naming it here.
FROM docker.io/library/debian:bookworm-slim

ARG PG_MAJOR=18
ARG PGRX_VERSION=0.19.2

RUN apt-get update \
 && apt-get install -y --no-install-recommends ca-certificates curl \
 && install -d /usr/share/postgresql-common/pgdg \
 && curl -fsSo /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc \
      https://www.postgresql.org/media/keys/ACCC4CF8.asc \
 && echo "deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.asc] https://apt.postgresql.org/pub/repos/apt bookworm-pgdg main $PG_MAJOR" \
      > /etc/apt/sources.list.d/pgdg.list \
 && apt-get update \
 && apt-get install -y --no-install-recommends \
      postgresql-$PG_MAJOR postgresql-server-dev-$PG_MAJOR \
      build-essential clang libclang-dev pkg-config git make \
 && rm -rf /var/lib/apt/lists/*

# Not root: initdb refuses root, and a stranger's machine is not run as root either. The
# user owns the PostgreSQL directories pgrx's unit tests and `make install` write into.
RUN useradd -m tester \
 && chown -R tester /usr/lib/postgresql/$PG_MAJOR/lib /usr/share/postgresql/$PG_MAJOR/extension
USER tester
ENV PATH=/home/tester/.cargo/bin:/usr/lib/postgresql/$PG_MAJOR/bin:$PATH \
    PG_CONFIG=/usr/lib/postgresql/$PG_MAJOR/bin/pg_config \
    USER=tester

RUN curl -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal
RUN cargo install cargo-pgrx --version "$PGRX_VERSION" --locked
RUN cargo pgrx init --pg$PG_MAJOR "$PG_CONFIG"

# The one dependency outside this repository, from its public repository.
RUN git clone --depth 1 https://github.com/Manuelreyesbravo/pg_living_assertions /home/tester/pg_living_assertions \
 && make -C /home/tester/pg_living_assertions install PG_CONFIG="$PG_CONFIG"

COPY --chown=tester . /home/tester/pg_agent_gate
WORKDIR /home/tester/pg_agent_gate
CMD ["make", "verify"]
