#!/bin/sh
# =============================================================================
# Soverise Linux Agent — installer
#
# Served by the deployment it installs FROM, so the agent it puts on the board
# is the one that deployment expects and the cloud endpoints are already
# correct. There is no third-party release host in this path.
#
#   curl -sSL https://get.<domain>/linux/install.sh | sudo bash
#
# Installs from source: a venv under /opt/soverise, the agent package into it,
# and /etc/soverise/env carrying this deployment's endpoints. The Rust services
# (mavlink-router, video, crsf, plugin-host) are NOT built here — cloud
# pairing, telemetry and the MQTT lanes do not need them, and building them on
# an SBC takes longer than most people will wait. Build them later with
# `cargo build --release` from /opt/soverise/src/crates.
# =============================================================================
set -eu

# Where this script was served from decides where its payload comes from, so a
# self-host never accidentally pulls another deployment's build.
BASE="${SOVERISE_DOWNLOADS_BASE:-https://get.soverise.metareignity.com}"
SRC_URL="${BASE}/linux/soverise-agent-src.tgz"

INSTALL_DIR="${SOVERISE_INSTALL_DIR:-/opt/soverise}"
CONFIG_DIR="/etc/soverise"
VENV="${INSTALL_DIR}/venv"

log()  { printf '\033[0;36m==>\033[0m %s\n' "$*"; }
warn() { printf '\033[0;33mwarn:\033[0m %s\n' "$*" >&2; }
die()  { printf '\033[0;31mERROR:\033[0m %s\n' "$*" >&2; exit 1; }

[ "$(id -u)" -eq 0 ] || die "run with sudo — this writes ${INSTALL_DIR} and ${CONFIG_DIR}"

# Fail on the missing prerequisite by NAME rather than on the first cryptic
# error it causes three steps later.
for tool in curl tar python3; do
    command -v "$tool" >/dev/null 2>&1 || die "$tool is required but not installed"
done
python3 -c 'import venv' >/dev/null 2>&1 \
    || die "python3-venv is required (apt install python3-venv)"

log "Downloading the agent from ${BASE}"
TMP="$(mktemp -d)"
trap 'rm -rf "$TMP"' EXIT
curl -fsSL "$SRC_URL" -o "$TMP/src.tgz" \
    || die "could not fetch ${SRC_URL}"

log "Unpacking to ${INSTALL_DIR}/src"
mkdir -p "$INSTALL_DIR/src"
tar -xzf "$TMP/src.tgz" -C "$INSTALL_DIR/src"

log "Creating the virtualenv"
[ -d "$VENV" ] || python3 -m venv "$VENV"
"$VENV/bin/pip" install --quiet --upgrade pip
log "Installing the agent (this takes a few minutes on an SBC)"
"$VENV/bin/pip" install --quiet -e "$INSTALL_DIR/src"

# Deployment endpoints, written the same way the Rust installer does it:
# SET-IF-ABSENT, because this file is operator-owned after its first write and
# an upgrade must never silently re-point a configured node at another cloud.
mkdir -p "$CONFIG_DIR"
if [ -f "$CONFIG_DIR/env" ]; then
    log "Keeping the existing ${CONFIG_DIR}/env"
else
    log "Writing ${CONFIG_DIR}/env"
    HOST="${BASE#https://get.}"
    cat > "$CONFIG_DIR/env" <<ENVEOF
# Soverise deployment defaults (written by the installer). The agent treats
# these as config DEFAULTS — a value in config.yaml overrides them.
SOVERISE_CONVEX_URL=https://convex-site.${HOST}
SOVERISE_MQTT_BROKER=mqtt.${HOST}
SOVERISE_MQTT_PORT=8883
ENVEOF
    chmod 0644 "$CONFIG_DIR/env"
fi

ln -sf "$VENV/bin/soverise" /usr/local/bin/soverise 2>/dev/null || true

cat <<DONE

  Installed.

  Next:
      soverise status          # prints this node's claim link
  Open that link (or scan the QR it shows) to adopt the node into your
  organization. The endpoints in ${CONFIG_DIR}/env point at this deployment
  already, so there is nothing else to configure.

DONE
