#!/usr/bin/env bash # Bridge bootstrap. Public, contains nothing secret. Usage: # # curl -fsSL https://bridge.halcyon.infi2.com | bash # # Makes sure the GitHub CLI is installed (on a Mac, installing Homebrew first # if there is none), walks you through logging in to GitHub, then fetches the # real installer from the private infi2-dev/bridge repository and runs it with # any arguments you pass, e.g. curl -fsSL https://bridge.halcyon.infi2.com | bash -s -- --check set -euo pipefail REPO="${BRIDGE_REPO:-infi2-dev/bridge}" REF="${BRIDGE_REF:-main}" say() { printf '\n\033[1m%s\033[0m\n' "$*"; } have() { command -v "$1" >/dev/null 2>&1; } fail() { printf '\n\033[1;31m%s\033[0m\n' "$*" >&2; exit 1; } # Piped through bash, stdin is the script itself; talk to the user through the terminal. exec 3> "$profile" echo "Added Homebrew to $profile, so new terminals find it." fi } if [ "$(uname -s)" = "Darwin" ]; then if find_brew; then persist_brew else say "Installing Homebrew" cat <<'EOF' Homebrew is the package manager Bridge uses on a Mac, for the GitHub CLI and PostgreSQL. Its installer will: - ask for your Mac password (the one you log in with; nothing appears as you type, which is normal), and your Mac account must be an administrator; - ask you to press Return to continue; - possibly install Apple's command line tools first, which can take ten minutes or more. Let it finish. EOF /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)" <&3 \ || fail "Homebrew did not install. Fix what it reported, then run this installer again." find_brew || fail "Homebrew installed but cannot be found. Open a new terminal and run this installer again." persist_brew fi fi # ----- The GitHub CLI -------------------------------------------------------------- if have gh; then echo "GitHub CLI: $(gh --version | head -1)" else say "Installing the GitHub CLI" if have brew; then brew install gh elif have apt-get; then if ! apt-cache show gh >/dev/null 2>&1; then sudo mkdir -p -m 755 /etc/apt/keyrings curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo tee /etc/apt/keyrings/githubcli-archive-keyring.gpg >/dev/null echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list >/dev/null sudo apt-get update -qq fi sudo apt-get install -y -qq gh elif have pacman; then sudo pacman -S --needed --noconfirm github-cli else fail "Bridge supports macOS, Ubuntu/Debian and Arch. On this system, install the GitHub CLI yourself (https://cli.github.com) and run this installer again." fi <&3 have gh || fail "The GitHub CLI did not install. Fix what was reported above, then run this installer again." fi # ----- Logging in to GitHub ---------------------------------------------------------- if ! gh auth status >/dev/null 2>&1; then say "Log in to GitHub" cat <<'EOF' Use the GitHub account that has been given access to infi2-dev. If you do not have one yet, create one at https://github.com/signup and send the username to whoever gave you this link. What happens next. It may first ask whether to authenticate Git with your GitHub credentials: answer Yes. Then: 1. You are shown a one-time code, eight characters like ABCD-1234. Copy it. 2. Press Return and your browser opens https://github.com/login/device. If no browser opens (over SSH, or in WSL), open that address yourself, on any computer. 3. Sign in if asked, paste the code, and click Authorize. 4. Come back here. It carries on by itself. EOF gh auth login --hostname github.com --web --git-protocol https <&3 \ || fail "The GitHub login did not finish. Run this installer again to try again." fi login="$(gh api user --jq .login 2>/dev/null || echo '?')" echo "Logged in to GitHub as $login." if ! gh repo view "$REPO" --json name >/dev/null 2>&1; then fail "The GitHub account '$login' cannot see $REPO. - Wrong account? Run gh auth logout and then this installer again. - Right account? Ask whoever gave you this link to add '$login' to the infi2-dev organisation. GitHub then emails you an invitation: accept it, and run this installer again." fi say "Fetching the installer from $REPO@$REF" installer="$(mktemp -t bridge-install.XXXXXX)" trap 'rm -f "$installer"' EXIT gh api "repos/$REPO/contents/install.sh?ref=$REF" -H 'Accept: application/vnd.github.raw+json' > "$installer" BRIDGE_REPO="$REPO" BRIDGE_REF="$REF" bash "$installer" "$@" <&3