#!/usr/bin/env bash
set -euo pipefail

event_name="${GITHUB_EVENT_NAME:-}"
git_ref="${GITHUB_REF:-}"

if [[ "$event_name" != "push" || "$git_ref" != "refs/heads/main" ]]; then
  echo "Skipping bootstrap apply: only push events on main may apply"
  exit 0
fi

if [[ ! -f bootstrap/config.yaml ]] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
  echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled"
  exit 0
fi

if [[ -z "${KUBECONFIG_B64:-}" ]]; then
  echo "KUBECONFIG_B64 secret is required to apply bootstrap/applicationset.yaml"
  exit 1
fi

curl -fsSL "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" \
  -o /usr/local/bin/kubectl
chmod +x /usr/local/bin/kubectl

mkdir -p "${HOME}/.kube"
printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config"

if ! kubectl config current-context >/dev/null 2>&1; then
  echo "Skipping bootstrap apply: kubeconfig secret is not usable in this runner"
  exit 0
fi

# Apply both ApplicationSets (multi-document YAML)
kubectl apply -f bootstrap/applicationset.yaml
