/*
 * Copyright (C) 2023 Das Land Schleswig-Holstein vertreten durch den
 * Ministerpräsidenten des Landes Schleswig-Holstein
 * Staatskanzlei
 * Abteilung Digitalisierung und zentrales IT-Management der Landesregierung
 *
 * Lizenziert unter der EUPL, Version 1.2 oder - sobald
 * diese von der Europäischen Kommission genehmigt wurden -
 * Folgeversionen der EUPL ("Lizenz");
 * Sie dürfen dieses Werk ausschließlich gemäß
 * dieser Lizenz nutzen.
 * Eine Kopie der Lizenz finden Sie hier:
 *
 * https://joinup.ec.europa.eu/collection/eupl/eupl-text-eupl-12
 *
 * Sofern nicht durch anwendbare Rechtsvorschriften
 * gefordert oder in schriftlicher Form vereinbart, wird
 * die unter der Lizenz verbreitete Software "so wie sie
 * ist", OHNE JEGLICHE GEWÄHRLEISTUNG ODER BEDINGUNGEN -
 * ausdrücklich oder stillschweigend - verbreitet.
 * Die sprachspezifischen Genehmigungen und Beschränkungen
 * unter der Lizenz sind dem Lizenztext zu entnehmen.
 */
pipeline {
    agent {
        node {
            label 'ozgcloud-jenkins-build-agent-jdk21-node20'
        }
    }

    environment {
        BLUE_OCEAN_URL = "https://jenkins.infra.ozg-cloud.systems/job/alfa/job/${env.BRANCH_NAME}/${env.BUILD_NUMBER}/"
        RELEASE_REGEX = /\d+.\d+.\d+/
        SNAPSHOT_REGEX = /\d+.\d+.\d+-SNAPSHOT/
        FAILED_STAGE = ""
        SH_SUCCESS_STATUS_CODE = 0
        FORCE_COLOR = 0
        NO_COLOR = 1
        NX_DISABLE_DB = true
        IMAGE_TAG = buildVersionName()
    }

    options {
        timeout(time: 1, unit: 'HOURS')
        disableConcurrentBuilds()
        buildDiscarder(logRotator(numToKeepStr: '5'))
    }

    stages {
        stage('Check Version') {
            steps {
                script {
                    FAILED_STAGE = env.STAGE_NAME
                    VERSION = getRootPomVersion()
                    def serverVersion = getParentPomVersion('alfa-server/pom.xml')

                    if(isReleaseBranch()){
                        if ( !isReleaseVersion([VERSION, serverVersion]) ) {
                            error("Keine Release Version für Branch ${env.BRANCH_NAME}.")
                        }
                    } else {
                        if ( !isSnapshotVersion([VERSION, serverVersion]) ) {
                            error("Keine Snapshot Version für Branch ${env.BRANCH_NAME}.")
                        }
                    }
                }
            }
        }

        stage('Set Version') {
          when {
            not {
                anyOf {
                    branch 'main'
                    branch 'release'
                }
            }
          }
          steps {
                script {
                    FAILED_STAGE=env.STAGE_NAME
                    JAR_TAG = getRootPomVersion().replace("SNAPSHOT", "${env.BRANCH_NAME}-SNAPSHOT")
                }
                configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                    sh "mvn -s $MAVEN_SETTINGS versions:set -DnewVersion=${JAR_TAG} -DprocessAllModules=true"

                }
          }
        }

        stage('Build Server artifacts, build and push docker image') {
            steps {
                script {
                    FAILED_STAGE=env.STAGE_NAME

                    configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                        sh 'mvn --version'
                        sh "mvn -s $MAVEN_SETTINGS clean install"
                        sh "mvn --no-transfer-progress -s $MAVEN_SETTINGS spring-boot:build-image -Dspring-boot.build-image.imageName=docker.ozg-sh.de/alfa:${IMAGE_TAG} -Dspring-boot.build-image.publish -Dmaven.wagon.http.retryHandler.count=3"

 						if (isMainBranch()) {
	                   		try {
	    	                    dir('alfa-service'){
	                                withSonarQubeEnv('sonarqube-ozg-sh'){
	                                    sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS sonar:sonar'
	                                }
	                            }
	                        }
	                        catch (Exception e) {
	                            unstable("SonarQube failed")
	                        }
	                    }
                    }
                }
            }
            post {
                always{
                    junit testResults: '**/target/surefire-reports/*.xml', skipPublishingChecks: true
                }
            }
        }
        stage('Deploy Maven Artifacts to Nexus') {
            steps {
                script {
                    FAILED_STAGE = env.STAGE_NAME
                }

                configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                    sh 'mvn --no-transfer-progress -s $MAVEN_SETTINGS -DskipTests deploy'
                    sh "mvn -s $MAVEN_SETTINGS versions:revert"
                }
            }
        }
        stage('Tag and Push Docker Image') {
            when {
                anyOf {
                    branch 'main'
                    branch 'release'
                }
            }

            steps {
                script {
                    FAILED_STAGE = env.STAGE_NAME

                    if (isMainBranch()) {
                        tagAndPushDockerImage('snapshot-latest')
                    }
                    else if (isReleaseBranch()) {
                        tagAndPushDockerImage('latest')
                    }
                }
            }
        }

        stage('Test, build and deploy Alfa Helm Chart') {
            steps {
                script {
                    FAILED_STAGE=env.STAGE_NAME
                    HELM_CHART_VERSION = buildVersionName()

                    sh "./run_helm_test.sh"

                    dir('src/main/helm') {

                        sh "helm package --version=${HELM_CHART_VERSION} ."

                        deployHelmChart(HELM_CHART_VERSION, "alfa")
                    }
                }
            }
        }

        stage('Trigger Dev rollout') {
            when {
                branch 'main'
            }
            steps {
                script {
                    FAILED_STAGE = env.STAGE_NAME

                    cloneGitopsRepo()

                    setNewDevVersion()
                    pushGitopsRepo()
                }
            }
        }

        stage('Trigger Test rollout') {
            when {
                branch 'release'
            }
            steps {
                script {
                    FAILED_STAGE = env.STAGE_NAME

                    cloneGitopsRepo()

                    setNewTestVersion()
                    pushGitopsRepo()
                }
            }
        }

        stage ('Deploy SBOM to DependencyTrack') {
            steps {
                script {
                    configFileProvider([configFile(fileId: 'maven-settings', variable: 'MAVEN_SETTINGS')]) {
                        withCredentials([string(credentialsId: 'dependency-track-api-key', variable: 'API_KEY')]) {

                            dir('alfa-server') {
                                catchError(buildResult: 'UNSTABLE', stageResult: 'FAILURE') {
                                    sh "mvn  --no-transfer-progress -s $MAVEN_SETTINGS io.github.pmckeown:dependency-track-maven-plugin:upload-bom -Ddependency-track.apiKey=$API_KEY -Ddependency-track.projectVersion=${IMAGE_TAG} -Ddependency-track.dependencyTrackBaseUrl=https://dependency-track.ozg-sh.de"
                                }
                            }
                        }
                    }
                }
            }
        }
    }
    post {
        failure {
            script {
                if (isMainBranch() || isReleaseBranch()) {
                    sendFailureMessage()
                }
            }
        }
    }
}

Void deployHelmChart(String helmChartVersion, String app ) {
    withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USERNAME', passwordVariable: 'PASSWORD')]){
        if (isReleaseBranch()) {
            result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps -F file=@'''+app+'''-'''+helmChartVersion+'''.tgz''', returnStdout: true
        }
        else {
            result = sh script: '''curl -u $USERNAME:$PASSWORD https://nexus.ozg-sh.de/service/rest/v1/components?repository=ozg-base-apps-snapshot -F file=@'''+app+'''-'''+helmChartVersion+'''.tgz''', returnStdout: true
        }

        if (result != '') {
            error(result)
        }
    }
}

String validateBranchName(branchName) {
    int maxLength = 30
    if (branchName.length() > maxLength) {
        String originalBranchName = branchName
        branchName = branchName.substring(0, maxLength)
        echo "WARNING: Branch name '${originalBranchName}' exceeded ${maxLength} characters. " +
             "It has been truncated to '${branchName}' for deployment purposes."
    }
    return branchName
}

String buildVersionName() {
    if (isReleaseBranch()) {
        return getRootPomVersion()
    }

    return "${getRootPomVersion()}-${validateBranchName(env.BRANCH_NAME)}${getCommitHash()}".replaceAll("_", "-")
}

Void tagAndPushDockerImage(String newTag){
    withCredentials([usernamePassword(credentialsId: 'jenkins-nexus-login', usernameVariable: 'USER', passwordVariable: 'PASSWORD')]) {
        sh 'docker login docker.ozg-sh.de -u ${USER} -p ${PASSWORD}'

        sh "docker tag docker.ozg-sh.de/alfa:${IMAGE_TAG} docker.ozg-sh.de/alfa:${newTag}"
        sh "docker push docker.ozg-sh.de/alfa:${newTag}"
    }
}

Void cloneGitopsRepo() {
    withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
        sh 'git clone https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
    }
    configureGit()
}

Void pushGitopsRepo() {
    withCredentials([usernamePassword(credentialsId: 'jenkins-gitea-access-token', passwordVariable: 'TOKEN', usernameVariable: 'USER')]) {
        dir("gitops") {
            if (hasUnpushedCommits()) {
                sh 'git push https://${USER}:${TOKEN}@git.ozg-sh.de/ozgcloud-devops/gitops.git'
            }
        }
    }
}

Boolean hasUnpushedCommits() {
    return sh (script: "git cherry -v | grep .", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
}

Void configureGit() {
    final email = "jenkins@ozg-sh.de"
    final name = "jenkins"

    dir("gitops") {
        sh "git config user.email '${email}'"
        sh "git config user.name '${name}'"
    }
}

Void sendFailureMessage() {
    def room = ''
    def data = """{"msgtype":"m.text", \
                    "body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: ${env.BUILD_NUMBER} Link: ${BLUE_OCEAN_URL}", \
                    "format": "org.matrix.custom.html", \
                    "formatted_body":"Alfa: Build Failed. Stage: ${FAILED_STAGE} Build-ID: <a href='${BLUE_OCEAN_URL}'>${env.BUILD_NUMBER}</a>"}"""

    if (isMainBranch()) {
        room = "!iQPAvQIiRwRpNOszjw:matrix.ozg-sh.de"
    }
    else if (isReleaseBranch()) {
        room = "!oWZpUGTFsxkJIYNfYg:matrix.ozg-sh.de"
    }

    sh "curl -XPOST -H 'authorization: Bearer ${getElementAccessToken()}' -d '${data}' https://matrix.ozg-sh.de/_matrix/client/v3/rooms/$room/send/m.room.message"
}

String getElementAccessToken() {
    withCredentials([string(credentialsId: 'element-login-json', variable: 'LOGIN_JSON')]) {
        return readJSON ( text: sh (script: '''curl -XPOST -d \"$LOGIN_JSON\" https://matrix.ozg-sh.de/_matrix/client/v3/login''', returnStdout: true)).access_token
    }
}

Void setNewDevVersion() {
    setNewGitopsVersion("dev")

}

Void setNewTestVersion() {
    setNewGitopsVersion("test")
}

Void setNewGitopsVersion(String environment) {
    def envFile = "${environment}/application/values/alfa-values.yaml"
    def commitMessage = "jenkins rollout ${environment} alfa version ${IMAGE_TAG}";
    setNewAlfaGitopsVersion(envFile, commitMessage);
}

Void setNewAlfaGitopsVersion(String envFile, String commitMessage) {
    dir("gitops") {
        def envVersions = readYaml file: envFile

        envVersions.alfa.image.tag = IMAGE_TAG
        envVersions.alfa.helm.version = HELM_CHART_VERSION

        writeYaml file: envFile, data: envVersions, overwrite: true

        if (hasValuesFileChanged(envFile)) {
            sh "git add ${envFile}"
            sh "git commit -m '${commitMessage}'"
        }
    }
}

String getCommitHash() {
    return "-${env.GIT_COMMIT.take(7)}";
}

Boolean hasValuesFileChanged(String envFile) {
    return sh (script: "git status | grep '${envFile}'", returnStatus: true) == env.SH_SUCCESS_STATUS_CODE as Integer
}

Boolean isReleaseBranch() {
    return env.BRANCH_NAME == 'release'
}

Boolean isMainBranch() {
    return env.BRANCH_NAME == 'main'
}

Boolean isReleaseVersion(List versions) {
    return matchRegexVersion(versions, RELEASE_REGEX)
}

Boolean isSnapshotVersion(List versions) {
    return matchRegexVersion(versions, SNAPSHOT_REGEX)
}

Boolean matchRegexVersion(List versions, String regex) {
    for (version in versions) {
        println version
        if ( !(version ==~ regex) ) {
            return false
        }
    }

    return true
}

Boolean isSameVersion(List versions, String expectedVersion) {
    for (version in versions) {
        if ( version != expectedVersion ) {
            return false
        }
    }

    return true
}

String getRootPomVersion() {
    def rootPom = readMavenPom file: 'pom.xml'
    return rootPom.version
}

String getParentPomVersion(String filePath) {
    def pom = readMavenPom file: filePath
    return pom.parent.version
}