SHELL := /usr/bin/env bash
.DEFAULT_GOAL := help

AUDIT_CORE_MOCK_DIR ?= /tmp/audit-core

test: ## Run unit tests
	python3 -m pytest -q

mock-audit-smoke: ## Write one non-secret smoke event to the mock audit backend
	AUDIT_CORE_MOCK_DIR="$(AUDIT_CORE_MOCK_DIR)" python3 -m audit_core emit \
	  --source audit-core \
	  --action audit_core.mock_backend.smoke \
	  --resource "$(AUDIT_CORE_MOCK_DIR)" \
	  --outcome success \
	  --detail backend=mock-file

mock-audit-cleanup: ## Remove mock audit files older than the retention window
	AUDIT_CORE_MOCK_DIR="$(AUDIT_CORE_MOCK_DIR)" python3 -m audit_core cleanup

help: ## Show this help
	@awk 'BEGIN {FS = ":.*##"; printf "\nUsage:\n  make \033[36m<target>\033[0m\n"} \
	  /^[a-zA-Z_-]+:.*?##/ { printf "  \033[36m%-24s\033[0m %s\n", $$1, $$2 }' $(MAKEFILE_LIST)

.PHONY: test test-pg pg-test-up pg-test-down failure-matrix mock-audit-smoke mock-audit-cleanup \
	image-build image-publish deploy-dry-run help

IMAGE_REGISTRY ?= forgejo.coulomb.social/coulomb/audit-core
GIT_COMMIT := $(shell git rev-parse HEAD)
GIT_COMMIT_SHORT := $(shell git rev-parse --short HEAD)
# railiance01 k3s API is forwarded by ops-bridge tunnel k3s-api-railiance01.
KUBECONFIG_RAILIANCE ?= $(HOME)/.kube/config-hosteurope

image-build: ## Build the immutable image, labelled with the current commit
	docker build -f Containerfile \
	  --build-arg GIT_COMMIT=$(GIT_COMMIT) \
	  -t $(IMAGE_REGISTRY):$(GIT_COMMIT_SHORT) \
	  -t $(IMAGE_REGISTRY):$(GIT_COMMIT) \
	  .

image-publish: image-build ## Push the commit-tagged image to Forgejo
	docker push $(IMAGE_REGISTRY):$(GIT_COMMIT_SHORT)
	docker push $(IMAGE_REGISTRY):$(GIT_COMMIT)
	@echo "Pin the printed digest in deploy/audit-core.yaml and deploy/migrate-job.yaml"

deploy-dry-run: ## Server-side validate the railiance01 manifests
	KUBECONFIG=$(KUBECONFIG_RAILIANCE) kubectl apply --dry-run=server --validate=strict \
	  -f deploy/audit-core.yaml \
	  -f deploy/senders-scope.yaml \
	  -f deploy/networkpolicies.yaml \
	  -f deploy/clustersecretstore.yaml \
	  -f deploy/externalsecrets.yaml \
	  -f deploy/migrate-job.yaml

PG_TEST_CONTAINER ?= ac-pg-test
PG_TEST_PORT ?= 55445
PG_TEST_URL ?= postgresql://postgres:test@127.0.0.1:$(PG_TEST_PORT)/audit_core

pg-test-up: ## Start a throwaway PostgreSQL for backend conformance tests
	-docker rm -f $(PG_TEST_CONTAINER) 2>/dev/null
	docker run -d --name $(PG_TEST_CONTAINER) -e POSTGRES_PASSWORD=test \
	  -e POSTGRES_DB=audit_core -p 127.0.0.1:$(PG_TEST_PORT):5432 postgres:16-alpine
	@for i in $$(seq 1 40); do \
	  docker exec $(PG_TEST_CONTAINER) pg_isready -U postgres >/dev/null 2>&1 && exit 0; \
	  sleep 1; done; echo "postgres did not become ready" >&2; exit 1

pg-test-down: ## Remove the throwaway PostgreSQL
	-docker rm -f $(PG_TEST_CONTAINER)

test-pg: ## Run the suite including PostgreSQL conformance (needs pg-test-up)
	AUDIT_CORE_TEST_DATABASE_URL="$(PG_TEST_URL)" python3 -m pytest -q

failure-matrix: ## Run the delivery/retry/replay failure matrix (AUDIT-WP-0005-T05)
	python3 scripts/failure_matrix.py
