#!/bin/sh
# Edge Lite — quick-install bootstrap for Zen Mesh
# Source of truth: deploy/edge-lite/docker/release/install-edge-lite.sh (zen-platform repo)
# Version: 1.0.0
# Copyright (c) 2026 Zen Mesh. All rights reserved. Proprietary; unauthorized copying or distribution is prohibited.
#
# This is a bootstrap script — it fetches and verifies the canonical installer
# from the zen-platform release directory. The canonical script is the single
# source of truth; this bootstrap exists only because the public install URL
# (get.zen-mesh.io) routes through Vercel/zen-mesh.io.
#
# Usage: curl -fsSL https://get.zen-mesh.io | sh
#
# Non-claims:
#   - launch_ready = false
#   - customer_ready = false
#   - prod_live = false
#   - free_tier_ready = false
#   - zero_trust_complete = false

set -eu

# ── Configuration ──────────────────────────────────────────────────
# P138 E2: the old canonical URL (raw.githubusercontent.com/zenmesh/zen-platform/...)
# returns 404 — that repo is archived (superseded by zen-platform-v1). The
# canonical installer now publishes on the site itself, checksum-pinned.
CANONICAL_SCRIPT_URL="https://www.zen-mesh.io/edge-lite/install-edge-lite.sh"
SCRIPT_NAME="install-edge-lite.sh"
# SHA256 checksum of the canonical script (verified release; re-pinned per release;
# re-pinned 2026-10-05 for v1.0.1 — the set-u fix, caught by the clean-machine runner)
# Verify: sha256sum edge-lite/install.sh
CANONICAL_HASH="5172558b615d98c903eaa28b82b89e9dba85a76e011c2e967ee6b9b047300bc2"

# ── Colors / formatting ────────────────────────────────────────────
RED='\033[0;31m'
GREEN='\033[0;32m'
YELLOW='\033[1;33m'
NC='\033[0m' # No Color

# ── Preflight ──────────────────────────────────────────────────────
if [ "$(uname)" != "Linux" ] && [ "$(uname)" != "Darwin" ]; then
    echo "${RED}Error:${NC} Edge Lite requires Linux or macOS."
    exit 1
fi

if ! command -v curl >/dev/null 2>&1; then
    echo "${RED}Error:${NC} curl is required. Install curl and retry."
    exit 1
fi

# ── Fetch canonical installer ──────────────────────────────────────
echo "${GREEN}Edge Lite Quick Install${NC}"
echo "Fetching canonical installer from zen-platform..."
echo ""

tmpdir=$(mktemp -d)
trap 'rm -rf "$tmpdir"' EXIT

if ! curl -fsSL -o "$tmpdir/$SCRIPT_NAME" "$CANONICAL_SCRIPT_URL"; then
    echo "${RED}Error:${NC} Failed to download canonical installer from"
    echo "  $CANONICAL_SCRIPT_URL"
    echo ""
    echo "The get.zen-mesh.io install surface is design-partner eval only."
    echo "Contact zen@zen-mesh.io for the latest installer."
    exit 1
fi

# ── Verify checksum (when available) ──────────────────────────────
if [ -n "$CANONICAL_HASH" ]; then
    actual_hash=$(sha256sum "$tmpdir/$SCRIPT_NAME" | cut -d' ' -f1)
    if [ "$actual_hash" != "$CANONICAL_HASH" ]; then
        echo "${RED}Error:${NC} Checksum mismatch!"
        echo "  Expected: $CANONICAL_HASH"
        echo "  Got:      $actual_hash"
        exit 1
    fi
    echo "${GREEN}Checksum verified.${NC}"
fi

# ── Make executable and run ───────────────────────────────────────
chmod +x "$tmpdir/$SCRIPT_NAME"
echo "${GREEN}Running canonical installer...${NC}"
echo ""
exec "$tmpdir/$SCRIPT_NAME" "$@"
