#!/usr/bin/env bash set -euo pipefail ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) action=${1:-plan} remote_manifest=${2:-} ssh_target=${3:-whoneedhelp} remote_root=${WNH_PRODUCTION_REMOTE_ROOT:-/srv/who_need_help-production} expected_domain=${WNH_PRODUCTION_DOMAIN:-whoneedhelp.com} case "$action" in plan | apply) ;; *) echo "Usage: $0 [plan|apply] REMOTE_ROLLBACK_MANIFEST [SSH_TARGET]" >&2 exit 2 ;; esac if [[ -z "$remote_manifest" ]]; then echo "Provide the absolute rollback-manifest.txt path printed by a successful release." >&2 exit 2 fi case "$remote_manifest" in "$remote_root"/output/releases/*/rollback-manifest.txt) ;; *) echo "Rollback manifest must be below $remote_root/output/releases/." >&2 exit 2 ;; esac command -v ssh >/dev/null 2>&1 || { echo "Required command is unavailable: ssh" >&2 exit 2 } quote() { printf '%q' "$1" } remote_command() { local remote_action=$1 printf 'bash -s -- %s %s %s %s' \ "$(quote "$remote_action")" \ "$(quote "$remote_root")" \ "$(quote "$expected_domain")" \ "$(quote "$remote_manifest")" } ssh -o BatchMode=yes "$ssh_target" \ "$(remote_command plan)" \ <"$ROOT/scripts/production-rollback-remote.sh" if [[ "$action" == plan ]]; then echo "Production application rollback plan passed; no remote state was changed." exit 0 fi if [[ -z "${WNH_PRODUCTION_ROLLBACK_CONFIRM:-}" ]]; then echo "Rollback execution requires the exact confirmation token printed by plan:" >&2 echo "WNH_PRODUCTION_ROLLBACK_CONFIRM=... $0 apply $remote_manifest $ssh_target" >&2 exit 2 fi confirmation=$(quote "$WNH_PRODUCTION_ROLLBACK_CONFIRM") ssh -o BatchMode=yes "$ssh_target" \ "WNH_PRODUCTION_ROLLBACK_CONFIRM=$confirmation $(remote_command apply)" \ <"$ROOT/scripts/production-rollback-remote.sh" echo "Production application rollback and public health verification completed."