Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

scripts/local/check.sh

Raw
#!/usr/bin/env bash
set -euo pipefail

repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
cd "${repo_root}"

usage() {
  echo "usage: check.sh [read|write] [PATH...]" >&2
  exit 2
}

mode="write"
if [[ "${1:-}" == "read" || "${1:-}" == "write" ]]; then
  mode="$1"
  shift
fi

all=false
tofu=false
caddy=false
toad_gateway=false
quadlets=false
ci_quadlets=false
toad_quadlets=false
shell=false
tofu_targets=()
shell_files=()

tofu_scope_for_deleted_path() {
  local scope="$1"
  while [[ "${scope}" == "${repo_root}" || "${scope}" == "${repo_root}/"* ]]; do
    if [[ -d "${scope}" ]] && find "${scope}" -type f \( -name '*.tf' -o -name '*.tf.json' \) -print -quit | grep -q .; then
      printf '%s\n' "${scope}"
      return
    fi
    [[ "${scope}" == "${repo_root}" ]] && break
    scope="$(dirname "${scope}")"
  done
  printf '%s\n' "${repo_root}"
}

if [[ "$#" -eq 0 ]]; then
  all=true
else
  for path in "$@"; do
    absolute="$(realpath -m -- "${path}")"
    if [[ "${path}" == *.tf || "${path}" == *.tf.json ]]; then
      tofu=true
      if [[ -f "${absolute}" ]]; then
        tofu_targets+=("${path}")
      else
        tofu_targets+=("$(tofu_scope_for_deleted_path "${absolute}")")
      fi
    elif [[ -d "${absolute}" ]] && find "${absolute}" -type f \( -name '*.tf' -o -name '*.tf.json' \) -print -quit | grep -q .; then
      tofu=true
      tofu_targets+=("${path}")
    fi

    if [[ -f "${absolute}" && "${path}" == *.sh ]]; then
      shell=true
      shell_files+=("${absolute}")
    elif [[ -d "${absolute}" ]]; then
      while IFS= read -r -d '' shell_file; do
        shell=true
        shell_files+=("${shell_file}")
      done < <(find "${absolute}" -type f -name '*.sh' -print0)
    fi

    [[ "${absolute}" == "${repo_root}/modules/klops/templates/Caddyfile.tftpl" || "${repo_root}/modules/klops/templates/Caddyfile.tftpl" == "${absolute}"/* ]] && caddy=true
    [[ "${absolute}" == "${repo_root}/services/toad/deploy/gateway.Caddyfile" || "${repo_root}/services/toad/deploy/gateway.Caddyfile" == "${absolute}"/* ]] && toad_gateway=true
    [[ "${absolute}" == "${repo_root}/modules/klops/quadlets" || "${absolute}" == "${repo_root}/modules/klops/quadlets"/* || "${repo_root}/modules/klops/quadlets" == "${absolute}"/* ]] && quadlets=true
    [[ "${absolute}" == "${repo_root}/modules/klops/ci-quadlets" || "${absolute}" == "${repo_root}/modules/klops/ci-quadlets"/* || "${repo_root}/modules/klops/ci-quadlets" == "${absolute}"/* ]] && ci_quadlets=true
    [[ "${absolute}" == "${repo_root}/services/toad/deploy" || "${absolute}" == "${repo_root}/services/toad/deploy"/* || "${repo_root}/services/toad/deploy" == "${absolute}"/* ]] && toad_quadlets=true
  done
fi

if ${all}; then
  tofu=true
  caddy=true
  toad_gateway=true
  quadlets=true
  ci_quadlets=true
  toad_quadlets=true
  shell=true
  tofu_targets=(.)
fi

if ${tofu}; then
  if [[ "${mode}" == "read" ]]; then
    tofu fmt -check -recursive "${tofu_targets[@]}"
  else
    tofu fmt -recursive "${tofu_targets[@]}"
  fi
  tofu validate
fi

if ${shell}; then
  if ${all}; then
    scripts/local/shell-check.sh "${mode}"
  else
    scripts/local/shell-check.sh "${mode}" "${shell_files[@]}"
  fi
fi

if ${caddy}; then
  if [[ "${mode}" == "read" ]]; then
    caddy fmt --diff modules/klops/templates/Caddyfile.tftpl
  else
    caddy fmt --overwrite modules/klops/templates/Caddyfile.tftpl
  fi
  caddy_tmp="$(mktemp -d)"
  trap 'rm -rf "${caddy_tmp}"' EXIT
  cp modules/klops/templates/Caddyfile.tftpl "${caddy_tmp}/Caddyfile"
  printf 'basic_auth {\n  admin %s\n}\n' "\$2a\$14\$012345678901234567890uKDeHn0xi2oABCD123456789012345678" >"${caddy_tmp}/genie-basicauth.caddy"
  cp "${caddy_tmp}/genie-basicauth.caddy" "${caddy_tmp}/toad-basicauth.caddy"
  (
    cd "${caddy_tmp}"
    caddy adapt --config Caddyfile --adapter caddyfile
  ) | jq -e '
    any(.. | objects; .dial? == "unix//run/toad-ingress/http.sock")
    and any(.. | objects | select(has("host")); .host == ["toad.bugabinga.net"])
  ' >/dev/null
fi

if ${toad_gateway}; then
  gateway=services/toad/deploy/gateway.Caddyfile
  if [[ "${mode}" == "read" ]]; then
    caddy fmt --diff "${gateway}"
  else
    caddy fmt --overwrite "${gateway}"
  fi
  TOAD_WEB_HOST=toad.invalid caddy adapt --config "${gateway}" --adapter caddyfile | jq -e '
    all(.apps.http.servers[].listen[]; startswith("unix/"))
    and any(.. | objects | select(has("host")); .host == ["toad.invalid"] and .path == ["/", "/assets/*"])
  ' >/dev/null
fi

if ${quadlets}; then
  QUADLET_UNIT_DIRS="${repo_root}/modules/klops/quadlets" /usr/lib/systemd/system-generators/podman-system-generator --user --dryrun
fi

if ${ci_quadlets}; then
  QUADLET_UNIT_DIRS="${repo_root}/modules/klops/ci-quadlets" /usr/lib/systemd/system-generators/podman-system-generator --user --dryrun
fi

if ${toad_quadlets}; then
  QUADLET_UNIT_DIRS="${repo_root}/services/toad/deploy" /usr/lib/systemd/system-generators/podman-system-generator --user --dryrun
fi

"${repo_root}/scripts/local/go.sh" check "${mode}" "$@"