# The demo image is the front door for anyone without Rust, and nothing else in CI builds it.
# Build it and run the demo in it whenever the Dockerfile or its ignore list changes. amd64
# only (the GitHub runner); on an ARM Mac it would run emulated.
name: docker

on:
  pull_request:
    paths: ['Dockerfile', '.dockerignore']
  push:
    branches: [main]
    paths: ['Dockerfile', '.dockerignore']
  workflow_dispatch:

permissions:
  contents: read

concurrency:
  group: docker-${{ github.ref }}
  cancel-in-progress: true

jobs:
  image:
    name: build and run the demo image
    runs-on: ubuntu-24.04
    timeout-minutes: 30
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          persist-credentials: false   # keep even a read token out of .git/config for the docker build that follows

      - name: build the image
        run: docker build -t pg_agent_gate-demo:ci .

      # Fail unless the gate actually did its job, not just unless the demo exited 0: the
      # markers below are the refusals and limits in the output. A broken gate would be missing
      # "it proposes, it does not execute" or "refused at propose" or "aborted".
      - name: run the demo in it
        run: |
          docker run --rm pg_agent_gate-demo:ci | tee demo-output.txt
          for m in "it proposes, it does not execute" "refused at propose" \
                   "aborted" "TABLE GONE" "ana@new.example"; do
            grep -qF "$m" demo-output.txt || { echo "smoke test: the demo is missing: $m"; exit 1; }
          done
