set positional-arguments

# Flake host key. On macOS the LocalHostName is what matches the flake key
# (after the first rebuild); on Linux it's the plain hostname.
# Override:  just host=myname rebuild
host := if os() == "macos" { `scutil --get LocalHostName` } else { `hostname` }

# Pick the rebuild tool for the current OS.
rebuild-cmd := if os() == "macos" { "darwin-rebuild" } else { "nixos-rebuild" }

# Default: list available recipes.
default:
    @just --list

# Rebuild the system and switch immediately. Works on NixOS and macOS.
rebuild:
    sudo {{rebuild-cmd}} switch --flake .#{{host}}

# Update flake.lock
update:
    nix flake update

# Clean up old generations and optimize store, then bake the result for next boot
clean:
    sudo nix-collect-garbage --delete-older-than 7d
    sudo nix-store --optimise
    sudo {{ if os() == "macos" { "darwin-rebuild switch" } else { "nixos-rebuild boot" } }} --flake .#{{host}}

# Format every .nix file in the repo with nixfmt (RFC 166 style).
# Runs inside the devShell, so it works with or without direnv loaded.
fmt:
    nix develop -c bash -c "find . -name '*.nix' -not -path './iso/*' -not -path './.direnv/*' -exec nixfmt {} +"

# Lint Nix for anti-patterns (statix) and dead/unused bindings (deadnix).
# Exits nonzero on findings, so it doubles as a CI check.
lint:
    nix develop -c statix check .
    nix develop -c deadnix --fail .

# Preview what the next `rebuild` would change: build the target system
# without switching, then diff it against the running one.
diff:
    nix build --out-link /tmp/notfiles-next {{ if os() == "macos" { ".#darwinConfigurations." + host + ".system" } else { ".#nixosConfigurations." + host + ".config.system.build.toplevel" } }}
    nix develop -c nvd diff /run/current-system /tmp/notfiles-next

# Generate Ed25519 SSH keys for each named service (default: github gradescope).
# Override:  just gen-keys gitlab bitbucket
gen-keys *services='github gradescope h2p durrantlab signing_git scienting_git scienting_static_sites':
    @./scripts/gen-keys.sh {{services}}

# Download the latest NixOS installer ISO into iso/.
# Override defaults:  just fetch-iso --channel nixos-unstable --edition minimal
fetch-iso *args:
    @./scripts/fetch-iso.sh "$@"

# Write a bootable NixOS installer USB.
# Example:  just make-usb --iso iso/latest-nixos-graphical-x86_64-linux.iso
# The script self-elevates via sudo if needed.
make-usb *args:
    @./scripts/make-usb.sh "$@"

# Scaffold hosts/<name>/ and add a flake.nix entry.
# Example:  just register-host blackbear
register-host name:
    @./scripts/register-host.py --repo-root . "{{name}}"

# Capture the current machine's hardware into hosts/<name>/hardware.nix.
# Run this on the new machine.
# Example:  just capture-hardware blackbear
capture-hardware name:
    @./scripts/capture-hardware.sh "{{name}}"

# Show which hosts are currently registered in flake.nix.
hosts:
    @./scripts/list-hosts.py

# Seed ~/.docker/config.json and (for pass) set up the GPG key + pass store.
# Override store:   just docker-creds secretservice
# Unprotected key:  just docker-creds pass --no-passphrase
docker-creds store='pass' flag='':
    @./scripts/docker-creds.sh "{{store}}" "{{flag}}"
