# A machine that has never seen this project: Debian, PostgreSQL from the PostgreSQL # project's own apt repository, a stranger's toolchain, and the repository as git has it. # Everything the verification needs is installed here, from where anyone gets it, and # nothing comes from the machine that wrote the code. Built by tests/clean-machine/run.sh, # which is also what CI runs (.github/workflows/verify.yml) -- one definition of # "verified", not two that can drift. # # PG_MAJOR picks the version. PGDG publishes each major in its own component, betas # included, so 19 resolves to the newest 19 beta without naming it here. FROM docker.io/library/debian:bookworm-slim ARG PG_MAJOR=18 ARG PGRX_VERSION=0.19.2 RUN apt-get update \ && apt-get install -y --no-install-recommends ca-certificates curl \ && install -d /usr/share/postgresql-common/pgdg \ && curl -fsSo /usr/share/postgresql-common/pgdg/apt.postgresql.org.asc \ https://www.postgresql.org/media/keys/ACCC4CF8.asc \ && echo "deb [signed-by=/usr/share/postgresql-common/pgdg/apt.postgresql.org.asc] https://apt.postgresql.org/pub/repos/apt bookworm-pgdg main $PG_MAJOR" \ > /etc/apt/sources.list.d/pgdg.list \ && apt-get update \ && apt-get install -y --no-install-recommends \ postgresql-$PG_MAJOR postgresql-server-dev-$PG_MAJOR \ build-essential clang libclang-dev pkg-config git make \ && rm -rf /var/lib/apt/lists/* # Not root: initdb refuses root, and a stranger's machine is not run as root either. The # user owns the PostgreSQL directories pgrx's unit tests and `make install` write into. RUN useradd -m tester \ && chown -R tester /usr/lib/postgresql/$PG_MAJOR/lib /usr/share/postgresql/$PG_MAJOR/extension USER tester ENV PATH=/home/tester/.cargo/bin:/usr/lib/postgresql/$PG_MAJOR/bin:$PATH \ PG_CONFIG=/usr/lib/postgresql/$PG_MAJOR/bin/pg_config \ USER=tester RUN curl -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal RUN cargo install cargo-pgrx --version "$PGRX_VERSION" --locked RUN cargo pgrx init --pg$PG_MAJOR "$PG_CONFIG" # The one dependency outside this repository, from its public repository. RUN git clone --depth 1 https://github.com/Manuelreyesbravo/pg_living_assertions /home/tester/pg_living_assertions \ && make -C /home/tester/pg_living_assertions install PG_CONFIG="$PG_CONFIG" COPY --chown=tester . /home/tester/pg_agent_gate WORKDIR /home/tester/pg_agent_gate CMD ["make", "verify"]