# Copyright 2026 Zyvor · https://zyvor.dev
# SPDX-License-Identifier: Apache-2.0

# Real multi-host migration matrix. Requires a self-hosted runner with
# access to the Zyvor KVM lab and repository secrets (see docs/COMPATIBILITY.md).
# Skips cleanly when KAIRON_HW_LAB is not configured on the runner.
#
# validate: always runs on GitHub-hosted runners (PR/push) — script syntax,
# safety gate, and docs/COMPATIBILITY.md presence. Does not touch a cluster.
name: hardware-migration

on:
  workflow_dispatch:
  schedule:
    - cron: '0 3 * * *' # nightly 03:00 UTC
  pull_request:
  push:
    branches: [main]

permissions:
  contents: read

jobs:
  validate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1  # v7
      - name: Script syntax and safety gate
        run: |
          set -euo pipefail
          test -f docs/COMPATIBILITY.md
          for f in scripts/hardware-migration-matrix.sh scripts/recovery-drill.sh \
                   scripts/lab-inject-source-failure.sh scripts/lab-inject-controller-failover.sh \
                   scripts/lib/lab.sh; do
            bash -n "$f"
          done
          python3 -m py_compile scripts/lib/write_compat.py
          if [[ -f scripts/multi-host-migration-test-run.sh ]]; then
            bash -n scripts/multi-host-migration-test-run.sh
          fi
          # Safety gate must refuse without KAIRON_HW_LAB=1.
          if scripts/hardware-migration-matrix.sh 2>/tmp/hw-refuse.txt; then
            echo "expected refuse without KAIRON_HW_LAB=1" >&2
            exit 1
          fi
          grep -qi 'KAIRON_HW_LAB' /tmp/hw-refuse.txt
          echo "hardware-migration validate: OK"

  matrix:
    if: github.event_name == 'workflow_dispatch' || github.event_name == 'schedule'
    runs-on: [self-hosted, kairon-lab]
    steps:
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1  # v7
      - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e  # v7
        with:
          go-version: '1.27.x'
      - name: Build CLI
        run: make build
      - name: Run hardware migration matrix
        env:
          KAIRON_HW_LAB: ${{ vars.KAIRON_HW_LAB }}
          KAIRON_KUBE_URL: ${{ secrets.KAIRON_KUBE_URL }}
          KAIRON_KUBE_TOKEN: ${{ secrets.KAIRON_KUBE_TOKEN }}
          KAIRON_KUBE_CA_PEM: ${{ secrets.KAIRON_KUBE_CA }}
          KAIRON_HW_MACHINE: ${{ vars.KAIRON_HW_MACHINE }}
          KAIRON_HW_TARGET_NODE: ${{ vars.KAIRON_HW_TARGET_NODE }}
          KAIRON_HW_NAMESPACE: ${{ vars.KAIRON_HW_NAMESPACE }}
          KAIRON_HW_EBPF_MACHINE: ${{ vars.KAIRON_HW_EBPF_MACHINE }}
          KAIRON_HW_IMAGE: ${{ vars.KAIRON_HW_IMAGE }}
          KAIRON_HW_SOURCE_SSH: ${{ vars.KAIRON_HW_SOURCE_SSH }}
          KAIRON_HW_TARGET_SSH: ${{ vars.KAIRON_HW_TARGET_SSH }}
          KAIRON_HW_CONTROLLER_SSH: ${{ vars.KAIRON_HW_CONTROLLER_SSH }}
        run: |
          if [[ "${KAIRON_HW_LAB:-}" != "1" ]]; then
            echo "KAIRON_HW_LAB not set — skipping (configure lab vars/secrets to enable)."
            exit 0
          fi
          if [[ -n "${KAIRON_KUBE_CA_PEM:-}" ]]; then
            printf '%s\n' "$KAIRON_KUBE_CA_PEM" > "$RUNNER_TEMP/kube-ca.pem"
            export KAIRON_KUBE_CA="$RUNNER_TEMP/kube-ca.pem"
          fi
          export PATH="$PWD/bin:$PATH"
          set -o pipefail
          scripts/hardware-migration-matrix.sh --write-compat | tee matrix-out.txt
      - name: Upload COMPATIBILITY.md with results
        if: always()
        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a  # v7
        with:
          name: compatibility-md
          path: docs/COMPATIBILITY.md
          if-no-files-found: ignore
      - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a  # v7
        if: always()
        with:
          name: hardware-migration-matrix
          path: matrix-out.txt
          if-no-files-found: ignore
