#!/usr/bin/env bash
#MISE description="Run the database-backed integration tests against the local k3d stack's infra"
#MISE dir="{{config_root}}"
# Kube replacement for the compose-backed `mise docker:start && mise test:integration`:
# the tests boot the apps on this host but take their infrastructure — postgres
# (CNPG), the OIDC provider and the victoria pair — from the k3d cluster,
# port-forwarded to the same localhost ports the compose flow used.
#
# The S3-backed suites live in `mise test:integration:s3` instead, against the
# e2e stack's Ceph RGW — keeping Ceph out of here is what makes this quick.
#
# Prereq: mise k3d:up && mise tilt:ci-infra   (apps not required)
set -euo pipefail

[ "$(kubectl config current-context)" = "k3d-yucca" ] || {
  echo "Not on k3d-yucca. Run: mise k3d:up && mise tilt:ci-infra" >&2; exit 1; }

PF_PIDS=()
cleanup() {
  for p in "${PF_PIDS[@]:-}"; do kill "$p" 2>/dev/null || true; done
}
trap cleanup EXIT

wait_for() {
  local desc="$1"; shift
  for _ in $(seq 1 150); do "$@" >/dev/null 2>&1 && return 0; sleep 2; done
  echo "timed out waiting for $desc" >&2; return 1
}

echo "==> wait for infra"
wait_for "CNPG cluster Ready"  kubectl -n yucca wait --for=condition=Ready cluster/yucca-db --timeout=5s
wait_for "mock-oidc Available" kubectl -n yucca wait --for=condition=Available deploy/yucca-mock-oidc --timeout=5s

echo "==> port-forward infra to the localhost ports the tests expect"
kubectl port-forward -n yucca svc/yucca-db-rw      15432:5432 >/tmp/yucca-int-pf.log 2>&1 & PF_PIDS+=($!)
kubectl port-forward -n yucca svc/yucca-mock-oidc   8092:8092 >>/tmp/yucca-int-pf.log 2>&1 & PF_PIDS+=($!)
kubectl port-forward -n yucca svc/victoria-metrics  8428:8428 >>/tmp/yucca-int-pf.log 2>&1 & PF_PIDS+=($!)
kubectl port-forward -n yucca svc/victoria-logs     9428:9428 >>/tmp/yucca-int-pf.log 2>&1 & PF_PIDS+=($!)
probe() { (exec 3<>"/dev/tcp/localhost/$1") 2>/dev/null; }
for port in 15432 8092; do
  wait_for "localhost:$port" probe "$port"
done

echo "==> export cluster credentials (the per-package env files only set defaults)"
POSTGRES_HOST=localhost
POSTGRES_PORT=15432
POSTGRES_USERNAME="$(kubectl -n yucca get secret yucca-db-app -o jsonpath='{.data.username}' | base64 -d)"
POSTGRES_PASSWORD="$(kubectl -n yucca get secret yucca-db-app -o jsonpath='{.data.password}' | base64 -d)"
POSTGRES_DATABASE="$(kubectl -n yucca get secret yucca-db-app -o jsonpath='{.data.dbname}' | base64 -d)"
export POSTGRES_HOST POSTGRES_PORT POSTGRES_USERNAME POSTGRES_PASSWORD POSTGRES_DATABASE

# The deployed mock-oidc advertises its in-cluster name as the issuer; the dns
# preload resolves it to the port-forward for every node process (jest + the
# apps it boots). Same split-horizon glue as the e2e runner.
export OIDC_ISSUER=http://yucca-mock-oidc:8092
export OIDC_DEVICE_ISSUER=http://yucca-mock-oidc:8092
export NODE_OPTIONS="--require $PWD/packages/e2e/k3d/hostmap.cjs${NODE_OPTIONS:+ ${NODE_OPTIONS}}"

echo "==> run the database-backed integration suites"
# yucca-api and yucca-admin-api are serial against each other: both reset the
# same tables between tests. orchestration-api needs no infrastructure at all
# and rides along here because this is where integration suites are expected to
# run — the glob in `mise test:integration` had never matched its task name.
mise run --jobs 1 yucca-api:test:integration ::: yucca-admin-api:test:integration
mise run yucca-sdk:orchestration-api:test:integration
