# EXAMPLE / COPY INTO YOUR OWN REPOSITORY (not activated by downloading).
# Change the name "CI" below to your existing workflow name.
# This file is not automatically installed in anyone's account.
name: "Optional Machine Reflex evidence on failed CI"
on:
  workflow_run:
    workflows: ["CI"]
    types: [completed]
permissions:
  contents: read
jobs:
  free-reflex-quote:
    runs-on: ubuntu-latest
    timeout-minutes: 3
    # Never send a charge unless the organization configures both opt-in vars
    # and previously purchases/funds its own buyer API credits.
    env:
      REFLEX_EXECUTE_PAID: ${{ vars.REFLEX_EXECUTE_PAID || 'no' }}
      REFLEX_BUYER_AUTHORIZED: ${{ vars.REFLEX_BUYER_AUTHORIZED || 'no' }}
      REFLEX_MAX_PRICE_USD: "0.02"
      BOUNTY_API_KEY: ${{ secrets.BOUNTY_API_KEY }}
      GH_REPOSITORY: ${{ github.repository }}
      GH_RUN_ID: ${{ github.event.workflow_run.id }}
      GH_CONCLUSION: ${{ github.event.workflow_run.conclusion }}
    steps:
      - name: Prepare standard CloudEvents envelope
        shell: bash
        run: |
          node -e '
            const payload = {
              event: {
                specversion:"1.0",
                id:"github-ci-"+process.env.GH_RUN_ID,
                source:"/github/"+process.env.GH_REPOSITORY,
                type:"com.github.workflow.completed",
                data:{failure:Number(process.env.GH_CONCLUSION!=="success")}
              },
              policy:{
                expected_types:["com.github.workflow.completed"],
                metric_field:"failure", metric_max:0
              }
            };
            console.log(JSON.stringify(payload));
          ' > /tmp/reflex-event.json
      - name: Check event without paying by default
        shell: bash
        run: |
          curl --fail --show-error --location --proto '=https' --tlsv1.2 \
            https://bounty-engineer-x402-prod.onrender.com/machine-reflex-client.mjs \
            --output /tmp/machine-reflex-client.mjs
          node /tmp/machine-reflex-client.mjs < /tmp/reflex-event.json
# After inspecting this template, a customer can explicitly opt in to
# paid evidence only on failed runs with both repository variables set to yes,
# an existing funded API key saved as a secret, and a spending policy they own.
# No command deploys, creates payments or modifies repository content by itself.
