@echo off
set LOG=C:\atlas-bootstrap.log
echo === bootstrap begin %DATE% %TIME% === > %LOG%
set B=https://atlas-server.taile9cc75.ts.net/pc-fix-log/
powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri '%B%?m=bootstrap-start' -TimeoutSec 10" >> %LOG% 2>&1

set W=C:\atlas-fix
if not exist %W% mkdir %W%
powershell -NoProfile -Command "$ProgressPreference='SilentlyContinue'" >> %LOG% 2>&1

REM ---- 1. OpenSSH Server v9.5 stable (the v10 beta kills sessions; never use it) ----
if not exist "%W%\ssh95\OpenSSH-Win64\sshd.exe" (
  echo downloading OpenSSH v9.5 >> %LOG%
  powershell -NoProfile -Command "$ProgressPreference='SilentlyContinue'; Invoke-WebRequest -UseBasicParsing -Uri 'https://github.com/PowerShell/Win32-OpenSSH/releases/download/v9.5.0.0p1-Beta/OpenSSH-Win64.zip' -OutFile %W%\ssh95.zip -TimeoutSec 240" >> %LOG% 2>&1
  powershell -NoProfile -Command "Expand-Archive -Force %W%\ssh95.zip %W%\ssh95" >> %LOG% 2>&1
)
if exist "%W%\ssh95\OpenSSH-Win64\install-sshd.ps1" (
  powershell -NoProfile -ExecutionPolicy Bypass -File "%W%\ssh95\OpenSSH-Win64\install-sshd.ps1" >> %LOG% 2>&1
  powershell -NoProfile -Command "New-ItemProperty -Path 'HKLM:\SOFTWARE\OpenSSH' -Name DefaultShell -Value 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -PropertyType String -Force" >> %LOG% 2>&1
  powershell -NoProfile -Command "Set-Service sshd -StartupType Automatic; Set-Service ssh-agent -StartupType Automatic; Start-Service sshd" >> %LOG% 2>&1
  powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri '%B%?m=sshd-installed' -TimeoutSec 10" >> %LOG% 2>&1
) else (
  echo ssh zip missing >> %LOG%
  powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri '%B%?m=ERR-ssh-zip-missing' -TimeoutSec 10" >> %LOG% 2>&1
)

REM ---- 2. Atlas owner key (matches /root/.ssh/id_ed25519 on the VPS) ----
if not exist "C:\ProgramData\ssh" mkdir "C:\ProgramData\ssh"
echo ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGM7Xks4lASQeSHOLCefHSE7hT2UbTklaz2S8RxNP+5S atlas-funnel> "C:\ProgramData\ssh\administrators_authorized_keys"
powershell -NoProfile -Command "icacls 'C:\ProgramData\ssh\administrators_authorized_keys' /inheritance:r /grant 'SYSTEM:F' /grant 'BUILTIN\Administrators:F'" >> %LOG% 2>&1

REM ---- 3. firewall: 22 from tailscale range only ----
powershell -NoProfile -Command "if (Get-NetFirewallRule -Name 'atlas-sshd' -ErrorAction SilentlyContinue) { Set-NetFirewallRule -Name 'atlas-sshd' -RemoteAddress '100.64.0.0/10' -Enabled True } else { New-NetFirewallRule -Name 'atlas-sshd' -DisplayName 'OpenSSH (Atlas - Tailscale only)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22 -RemoteAddress '100.64.0.0/10' }" >> %LOG% 2>&1

REM ---- 4. Tailscale join (authkey dropped locally by SetupComplete) ----
if not exist "C:\Program Files\Tailscale\tailscale.exe" (
  echo downloading tailscale >> %LOG%
  powershell -NoProfile -Command "$ProgressPreference='SilentlyContinue'; Invoke-WebRequest -UseBasicParsing -Uri 'https://pkgs.tailscale.com/stable/tailscale-setup-1.80.2-amd64.msi' -OutFile C:\ts.msi -TimeoutSec 240" >> %LOG% 2>&1
  if exist C:\ts.msi msiexec /i C:\ts.msi /qn >> %LOG% 2>&1
  timeout /t 12 /nobreak >nul
)
if exist "C:\Program Files\Tailscale\tailscale.exe" (
  for /f "usebackq delims=" %%K in (`type C:\atlas-tskey.txt`) do set TSKEY=%%K
  "C:\Program Files\Tailscale\tailscale.exe" up --authkey %TSKEY% --hostname=atlas-home-win >> %LOG% 2>&1
  for /f "usebackq delims=" %%I in (`"C:\Program Files\Tailscale\tailscale.exe" ip -4`) do set TSIP=%%I
  powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri '%B%?m=tailscale-up-%TSIP%' -TimeoutSec 10" >> %LOG% 2>&1
) else (
  powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri '%B%?m=ERR-tailscale-missing' -TimeoutSec 10" >> %LOG% 2>&1
)

powershell -NoProfile -Command "Invoke-WebRequest -UseBasicParsing -Uri '%B%?m=bootstrap-done' -TimeoutSec 10" >> %LOG% 2>&1
echo === bootstrap exit === >> %LOG%
