#!/usr/bin/env bash
# One-time preparation of a fresh Ubuntu VPS for kaissflow.com.
# Run as root:  bash bootstrap-server.sh
#
# It does NOT issue the certificate or start the stack: both need secrets you
# have to paste in. See deploy/README.md for the order of operations.
set -Eeuo pipefail

DOMAIN=kaissflow.com
APP_ROOT=/opt/nacef

[[ $EUID -eq 0 ]] || { echo "run as root"; exit 1; }

echo "==> Base packages"
apt-get update
apt-get install -y --no-install-recommends \
  ca-certificates curl gnupg git ufw fail2ban unattended-upgrades \
  nginx certbot python3-certbot-nginx python3-certbot-dns-ovh

echo "==> Docker engine"
install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
chmod a+r /etc/apt/keyrings/docker.asc
echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] \
https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "$VERSION_CODENAME") stable" \
  > /etc/apt/sources.list.d/docker.list
apt-get update
apt-get install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
systemctl enable --now docker

echo "==> Service account + layout"
id -u nacef >/dev/null 2>&1 || useradd -r -m -d "$APP_ROOT" -s /bin/bash nacef
usermod -aG docker nacef
mkdir -p "$APP_ROOT/app" "$APP_ROOT/backups" /var/www/certbot
chown -R nacef:nacef "$APP_ROOT"

echo "==> Kernel + limits for Odoo/GitLab"
cat > /etc/sysctl.d/60-nacef.conf <<'EOF'
vm.max_map_count = 262144
vm.overcommit_memory = 1
net.core.somaxconn = 1024
EOF
sysctl --system >/dev/null

# GitLab and Odoo together will page without swap on a 24 GB box under load.
if ! swapon --show | grep -q .; then
  fallocate -l 8G /swapfile
  chmod 600 /swapfile
  mkswap /swapfile >/dev/null
  swapon /swapfile
  echo '/swapfile none swap sw 0 0' >> /etc/fstab
fi

echo "==> Firewall"
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp     comment 'ssh'
ufw allow 80/tcp     comment 'http / acme'
ufw allow 443/tcp    comment 'https'
ufw allow 2224/tcp   comment 'gitlab ssh'
ufw --force enable

echo "==> nginx"
rm -f /etc/nginx/sites-enabled/default
mkdir -p /etc/nginx/snippets
# Populated by the repo checkout; symlink now so a later git pull is enough.
ln -sfn "$APP_ROOT/app/deploy/nginx/kaissflow.conf" /etc/nginx/sites-available/kaissflow.conf
ln -sfn /etc/nginx/sites-available/kaissflow.conf   /etc/nginx/sites-enabled/kaissflow.conf
ln -sfn "$APP_ROOT/app/deploy/nginx/snippets/kaissflow-tls.conf"   /etc/nginx/snippets/kaissflow-tls.conf
ln -sfn "$APP_ROOT/app/deploy/nginx/snippets/kaissflow-proxy.conf" /etc/nginx/snippets/kaissflow-proxy.conf

echo "==> Certificate renewal hook"
mkdir -p /etc/letsencrypt/renewal-hooks/deploy
cat > /etc/letsencrypt/renewal-hooks/deploy/reload-nginx.sh <<'EOF'
#!/bin/sh
nginx -t && systemctl reload nginx
EOF
chmod +x /etc/letsencrypt/renewal-hooks/deploy/reload-nginx.sh

echo "==> Unattended security updates"
dpkg-reconfigure -f noninteractive unattended-upgrades

cat <<EOF

Bootstrap done. nginx will not start until the certificate exists.

Next, in order:
  1. git clone the repo into $APP_ROOT/app   (as the nacef user)
  2. cp deploy/.env.example deploy/.env and fill it in
  3. issue the wildcard cert (needs OVH API keys, see deploy/README.md)
  4. nginx -t && systemctl restart nginx
  5. docker compose -f deploy/docker-compose.yml up -d
  6. deploy/scripts/create-template.sh      <- creates masterdb + nacef_tpl
  7. DOCKER_GID=\$(getent group docker | cut -d: -f3) \\
       docker compose -f deploy/ci-compose.yml up -d --build
EOF
