#!/usr/bin/env bash
# Source inside the owning deploy shell. Never print the failed command or environment.
backend_report_failure() {
  local status="$1" phase="${BACKEND_DEPLOY_PHASE:-unclassified}"
  [ "$status" -ne 0 ] || return 0
  case "$phase" in
    validate_inputs|configure_ssh|sync_backend|write_runtime_env|remote_deploy|cleanup_key|\
    remote_setup|initialize_environment|compose_up|discover_port|local_health|configure_vhost|certificate|public_health) ;;
    *) phase=unclassified ;;
  esac
  # Multiline JSON secrets can make GitHub mask standalone braces. Keep fixed evidence readable.
  printf '::error title=backend_deploy_failed::gowalk-cicd/backend-deploy-failed.v1 phase=%s exit_code=%s\n' \
    "$phase" "$status"
  return "$status"
}

trap 'backend_report_failure "$?"' EXIT
