# Everything .env.production needs — the rendered file is COMPLETE, nothing
# is hand-edited afterwards:
#   terraform output -raw env_production > ../../.env.production
#   unoverse deploy && unoverse deploy db && unoverse deploy test

output "deploy_host" {
  description = ".env.production DEPLOY_HOST (SSH target). Public traffic goes to the ALB, never here."
  value       = aws_eip.app.public_ip
}

output "alb_dns_name" {
  description = "Point api.<domain> (and canvas.<domain> when canvas_public) at this — CNAME/ALIAS. Created automatically when route53_zone_id is set."
  value       = aws_lb.public.dns_name
}

output "acm_validation_records" {
  description = "External DNS only (domain set, route53_zone_id empty): create these CNAMEs so the certificate can issue."
  value = (local.has_domain && !local.dns_auto) ? [
    for dvo in aws_acm_certificate.public[0].domain_validation_options : {
      name = dvo.resource_record_name, type = dvo.resource_record_type, value = dvo.resource_record_value
    }
  ] : []
}

output "canvas_url" {
  description = "Public Canvas URL (canvas_public = true only) — add it to the client origins."
  value       = var.canvas_public ? local.canvas_entry : "canvas is admin-only (direct http://<instance-ip>:3001 from admin_cidr)"
}

output "api_url" {
  description = "The API base URL as deployed — https://api.<domain> with a domain, http://<alb-dns> without one."
  value       = local.has_domain ? "https://${local.api_host}" : "http://${aws_lb.public.dns_name}"
}

output "database_url" {
  description = ".env.production DATABASE_URL (sslmode=require: RDS enforces TLS by default on PG16 — rds.force_ssl=1 — so the client must ask for it)"
  value       = "postgresql://${aws_db_instance.postgres.username}:${random_password.db.result}@${aws_db_instance.postgres.address}:5432/${aws_db_instance.postgres.db_name}?sslmode=require"
  sensitive   = true
}

output "redis_host" {
  description = ".env.production REDIS_HOST (REDIS_PORT=6379, REDIS_TLS=true)"
  value       = aws_elasticache_replication_group.redis.primary_endpoint_address
}

output "redis_password" {
  description = ".env.production REDIS_PASSWORD"
  value       = random_password.redis.result
  sensitive   = true
}

output "auth_issuer" {
  description = ".env.production AUTH_ISSUER (the Cognito user pool issuer)"
  value       = "https://cognito-idp.${var.region}.amazonaws.com/${aws_cognito_user_pool.pool.id}"
}

output "auth_client_id" {
  description = ".env.production AUTH_CLIENT_ID — and the AUTH_AUDIENCE candidate: Cognito access tokens carry client_id, not aud. SMOKE-TEST audience validation with a real token before declaring the universe up (AWS_DEPLOYMENT.md)."
  value       = aws_cognito_user_pool_client.spa.id
}

output "roles" {
  description = "Every RBAC role provisioned as a Cognito group (platform permissions + var.roles)"
  value       = sort(keys(aws_cognito_user_group.roles))
}

output "cognito_hosted_ui" {
  description = "Hosted login domain (Managed Login)"
  value       = "https://${aws_cognito_user_pool_domain.domain.domain}.auth.${var.region}.amazoncognito.com"
}

output "bedrock_access_key_id" {
  description = "Store as a platform awsCredential (accessKeyId) for the Bedrock/Nova nodes"
  value       = one(aws_iam_access_key.bedrock[*].id)
}

output "bedrock_secret_access_key" {
  description = "Store as a platform awsCredential (secretAccessKey)"
  value       = one(aws_iam_access_key.bedrock[*].secret)
  sensitive   = true
}

# ── The whole .env.production, rendered COMPLETE ──────────────────────────────
output "env_production" {
  sensitive   = true
  description = "Rendered .env.production — complete, write to a file and deploy"
  value       = <<-ENV
    # UNIVERSE (AWS) — generated by infra/aws. COMPLETE:
    # do not hand-edit; change terraform.tfvars and re-render instead.

    # Deploy target (SSH; public traffic goes through the ALB)
    DEPLOY_HOST=${aws_eip.app.public_ip}
    DEPLOY_USER=ubuntu

    # Container registry
    DOCR_TOKEN=${var.docr_token}

    # Database (RDS enforces TLS on PG16 — sslmode stays). AWS runs DIRECT (no
    # pooler until `large` per the Postgres law): both URLs are the same server.
    DATABASE_URL=postgresql://${aws_db_instance.postgres.username}:${random_password.db.result}@${aws_db_instance.postgres.address}:5432/${aws_db_instance.postgres.db_name}?sslmode=require
    DATABASE_URL_DIRECT=postgresql://${aws_db_instance.postgres.username}:${random_password.db.result}@${aws_db_instance.postgres.address}:5432/${aws_db_instance.postgres.db_name}?sslmode=require

    # Connection budget (INFRASTRUCTURE.md, size = ${var.size})
    DB_POOL_ENGINE=${local.s.pool_engine}
    DB_POOL_ENGINE_LEGACY=${local.s.pool_legacy}
    DB_POOL_MEMORY=${local.s.pool_memory}

    # Credential encryption at rest — per-deployment, generated by Terraform.
    # Back this up with the database (a DB backup is unreadable without it).
    CREDENTIAL_ENCRYPTION_KEY=${random_password.credential_key.result}

    # Redis (ElastiCache, TLS + auth token)
    REDIS_HOST=${aws_elasticache_replication_group.redis.primary_endpoint_address}
    REDIS_PORT=6379
    REDIS_PASSWORD=${random_password.redis.result}
    REDIS_TLS=true
    REDIS_NAMESPACE=universe

    # OIDC (Cognito). AUTH_AUDIENCE = the app client id — Cognito access tokens
    # carry client_id, not aud; SMOKE-TEST with a real token (AWS_DEPLOYMENT.md).
    AUTH_ISSUER=https://cognito-idp.${var.region}.amazonaws.com/${aws_cognito_user_pool.pool.id}
    AUTH_CLIENT_ID=${aws_cognito_user_pool_client.spa.id}
    AUTH_AUDIENCE=${aws_cognito_user_pool_client.spa.id}

    # Service keys
    OPENAI_API_KEY=${var.openai_api_key}
    HYPERBROWSER_API_KEY=${var.hyperbrowser_api_key}

    # Marketplace catalogue (MARKETPLACE.md §5). Empty = local items only.
    UNOVERSE_MARKETPLACE_URL=${var.marketplace_url}

    # Ingress. With a domain: DOMAIN drives every URL (compose derives
    # https://api.<domain>). Without one (POC): DOMAIN stays empty and the
    # explicit URLs below point at the ALB's DNS name over plain HTTP.
    # To upgrade later: set domain in terraform.tfvars, terraform apply,
    # re-render this file, unoverse deploy. Nothing is destroyed.
    DOMAIN=${var.domain}
    ${local.has_domain ? "" : "API_URL=http://${aws_lb.public.dns_name}"}
    ${local.has_domain ? "" : "VITE_SERVER_WS_URL=ws://${aws_lb.public.dns_name}"}
    ${local.has_domain ? "" : "UNOVERSE_URL=http://${aws_lb.public.dns_name}"}
  ENV
}
