#!/bin/sh
# Install the Fillrate bare-metal runner once.
# New tasks do not need a new install. The runner only executes a task that
# Fillrate has signed, plus a one-time ticket for this machine and time window.
#
#   curl -fsSL https://fillrate.net/install/bare-metal.sh | sudo bash -s -- \
#     --machine-id 146922 --public-key 'ssh-ed25519 AAAA...'
#
# View the script before you run it: https://fillrate.net/install/bare-metal.sh
set -eu

ORIGIN=https://fillrate.net
RUNNER_SHA256=e4b024f315ca16e80fb0332c64238b9e9d121e6e9d25dd7c76acd16b9aad2fe3
JUMP_IP=134.199.240.201
MACHINE_ID=""
PUBLIC_KEY=""
TASK_PUB_FILE=""
TICKET_PUB_FILE=""
RUNNER_FILE=""

die() {
  printf '%s\n' "bare-metal install: $*" >&2
  exit 1
}

while [ $# -gt 0 ]; do
  case "$1" in
    --machine-id)
      MACHINE_ID=${2:-}
      shift 2
      ;;
    --public-key)
      PUBLIC_KEY=${2:-}
      shift 2
      ;;
    --origin)
      ORIGIN=${2:-}
      shift 2
      ;;
    --task-pub-file)
      TASK_PUB_FILE=${2:-}
      shift 2
      ;;
    --ticket-pub-file)
      TICKET_PUB_FILE=${2:-}
      shift 2
      ;;
    --runner-file)
      RUNNER_FILE=${2:-}
      shift 2
      ;;
    *)
      die "unknown argument: $1"
      ;;
  esac
done

[ "$(id -u)" -eq 0 ] || die "run as root"
printf '%s\n' "$MACHINE_ID" | grep -E -q '^[A-Za-z0-9._:-]{1,64}$' || die "machine-id is invalid"
case "$PUBLIC_KEY" in
  ssh-*) ;;
  *) die "public-key must be an OpenSSH public key line" ;;
esac

tmp=$(mktemp -d)
trap 'rm -rf "$tmp"' EXIT

if [ -n "$RUNNER_FILE" ]; then
  cp -- "$RUNNER_FILE" "$tmp/fillrate-runner"
else
  curl -fsSL "$ORIGIN/install/fillrate-runner" -o "$tmp/fillrate-runner" || die "could not download fillrate-runner"
fi
printf '%s  %s\n' "$RUNNER_SHA256" "$tmp/fillrate-runner" | sha256sum -c - || die "fillrate-runner checksum did not match"

if [ -n "$TASK_PUB_FILE" ]; then
  task_pub=$(sed -n '1p' "$TASK_PUB_FILE" | tr -d '\r')
else
  task_pub=""
fi
if [ -n "$TICKET_PUB_FILE" ]; then
  ticket_pub=$(sed -n '1p' "$TICKET_PUB_FILE" | tr -d '\r')
else
  ticket_pub=""
fi
if [ -z "$task_pub" ] || [ -z "$ticket_pub" ]; then
  keys=$(curl -fsSL "$ORIGIN/install/signing-keys") || die "could not download signing keys"
  [ -n "$task_pub" ] || task_pub=$(printf '%s\n' "$keys" | sed -n 's/^task //p' | sed -n '1p')
  [ -n "$ticket_pub" ] || ticket_pub=$(printf '%s\n' "$keys" | sed -n 's/^ticket //p' | sed -n '1p')
fi
case "$task_pub" in
  ssh-ed25519\ *) ;;
  *) die "task signing key is missing" ;;
esac
case "$ticket_pub" in
  ssh-ed25519\ *) ;;
  *) die "ticket signing key is missing" ;;
esac

printf '%s\n' "$PUBLIC_KEY" > "$tmp/host.pub"
ssh-keygen -l -f "$tmp/host.pub" >/dev/null 2>&1 || die "public key was rejected by ssh-keygen"
printf '%s\n' "$task_pub" > "$tmp/task.pub"
ssh-keygen -l -f "$tmp/task.pub" >/dev/null 2>&1 || die "task signing key was rejected by ssh-keygen"
printf '%s\n' "$ticket_pub" > "$tmp/ticket.pub"
ssh-keygen -l -f "$tmp/ticket.pub" >/dev/null 2>&1 || die "ticket signing key was rejected by ssh-keygen"

install -d -m 755 -o root -g root /etc/fillrate
printf '%s\n' "$MACHINE_ID" > /etc/fillrate/machine_id
printf '%s\n' "$task_pub" > /etc/fillrate/task-signing.pub
printf '%s\n' "$ticket_pub" > /etc/fillrate/ticket-signing.pub
chmod 644 /etc/fillrate/machine_id /etc/fillrate/task-signing.pub /etc/fillrate/ticket-signing.pub
chown root:root /etc/fillrate/machine_id /etc/fillrate/task-signing.pub /etc/fillrate/ticket-signing.pub

install -m 755 -o root -g root "$tmp/fillrate-runner" /usr/local/sbin/fillrate-runner

sudoers=$tmp/fillrate.sudoers
printf '%s\n' 'fillrate ALL=(root) NOPASSWD: /usr/local/sbin/fillrate-runner' > "$sudoers"
visudo -cf "$sudoers" >/dev/null || die "sudoers file failed visudo"
install -m 440 -o root -g root "$sudoers" /etc/sudoers.d/fillrate

if ! id fillrate >/dev/null 2>&1; then
  useradd --system --create-home --home-dir /var/lib/fillrate --shell /bin/bash --comment "Fillrate bare-metal runner" fillrate
fi
install -d -m 700 -o fillrate -g fillrate /var/lib/fillrate/.ssh
printf 'from="%s" %s\n' "$JUMP_IP" "$PUBLIC_KEY" > /var/lib/fillrate/.ssh/authorized_keys
chown fillrate:fillrate /var/lib/fillrate/.ssh/authorized_keys
chmod 600 /var/lib/fillrate/.ssh/authorized_keys
install -d -m 700 -o root -g root /var/lib/fillrate-runner

printf '%s\n' "Installed $(/usr/local/sbin/fillrate-runner version)"
printf '%s\n' "SSH user is fillrate. Access is limited to $JUMP_IP."
printf '%s\n' "Remove it with: sudo fillrate-runner uninstall"
