#!/usr/bin/env bash
#
# Fast auto-deploy for the standalone box. Installed as a ~60s systemd timer by
# scripts/standalone-deploy.sh. Polls the deploy branch; when new commits land,
# it pulls, rebuilds, and runs migrations. Push -> live in ~1-2 min, hands-off.
#
# Exits immediately (cheap) when there is nothing new, so a tight interval is fine.
set -euo pipefail

REPO_DIR="/opt/gluecron"
BRANCH="main"
COMPOSE="docker compose -f docker-compose.standalone.yml"

cd "$REPO_DIR"
git fetch origin "$BRANCH" --quiet

local_sha=$(git rev-parse HEAD)
remote_sha=$(git rev-parse "origin/$BRANCH")
[ "$local_sha" = "$remote_sha" ] && exit 0

echo "$(date -Is) deploying $local_sha -> $remote_sha"
git reset --hard "origin/$BRANCH"     # untracked .env / backups are preserved

# NOTE: `|| true` is deliberate. On this Coolify co-tenant box the compose
# also defines a `caddy` service that tries to bind host :80/:443, which
# Coolify's proxy already owns — so `up` reports a non-zero exit for caddy
# even though the app (gluecron) started fine. Under `set -e` that would abort
# the deploy BEFORE the coolify reattach + health gate below. We tolerate the
# partial failure here and instead gate on the app's OWN health further down.
$COMPOSE up -d --build || echo "$(date -Is) compose up returned non-zero (likely the co-tenant caddy port conflict) — continuing to app health gate"
sleep 5

# Co-tenant ingress reattach (Coolify boxes only).
# `docker compose up --build` recreates the gluecron container, which DROPS
# any network attachment not declared in docker-compose.standalone.yml. On
# this box the public ingress is Coolify's Traefik ("coolify-proxy"), which
# reaches the app over the external "coolify" network via the file route
# /traefik/dynamic/gluecron.yaml in the coolify-proxy container. Without this
# reattach, every deploy 502s the site until someone reconnects by hand.
# Idempotent: a no-op if already attached; skipped entirely on a dedicated VPS
# that has no "coolify" network.
if docker network inspect coolify >/dev/null 2>&1; then
  docker network connect coolify gluecron-gluecron-1 2>/dev/null \
    && echo "$(date -Is) reattached gluecron to coolify network" \
    || echo "$(date -Is) coolify network already attached (ok)"
fi

$COMPOSE exec -T gluecron bun run db:migrate || true
docker image prune -f >/dev/null 2>&1 || true

# App health gate — the real success signal (not caddy). Poll the container's
# own /healthz; if the app itself never comes up, exit non-zero so the systemd
# unit records a failed deploy instead of a silent green.
healthy=0
for _ in $(seq 1 20); do
  if docker exec gluecron-gluecron-1 wget -qO- --timeout=4 http://localhost:3000/healthz >/dev/null 2>&1; then
    healthy=1; break
  fi
  sleep 3
done
if [ "$healthy" != "1" ]; then
  echo "$(date -Is) DEPLOY FAILED: app /healthz never came up for $remote_sha" >&2
  exit 1
fi

echo "$(date -Is) deploy complete: $remote_sha (app healthy)"
