#!/bin/bash
# Base package installation, Nginx, PHP 8.5, MySQL
# If you need other PHP versions, use Docker.

if [ "$EUID" -ne 0 ]; then echo "Error: Run as root"; exit 1; fi

echo "==> Updating system and installing base utilities..."
apt update && apt upgrade -y
apt install -y software-properties-common curl wget unzip

echo "==> Installing Nginx, PHP 8.5 (from Ubuntu 26.04 default repo), and certbot..."
apt install -y nginx \
    php8.5-fpm php8.5-cli php8.5-mysql php8.5-xml php8.5-curl php8.5-mbstring php8.5-zip \
    php8.5-sqlite3 php8.5-gd php8.5-bcmath php8.5-intl php8.5-imagick  \
    certbot python3-certbot-nginx

echo "==> Installing MySQL Server..."
apt install -y mysql-server

echo "==> Basic MySQL hardening (non-interactive equivalent of mysql_secure_installation)..."
mysql <<'EOF'
DELETE FROM mysql.user WHERE User='';
DROP DATABASE IF EXISTS test;
DELETE FROM mysql.db WHERE Db='test' OR Db='test\\_%';
FLUSH PRIVILEGES;
EOF

echo "==> Checking MySQL bind-address (should default to 127.0.0.1)..."
grep -q "^bind-address" /etc/mysql/mysql.conf.d/mysqld.cnf && \
    echo "    bind-address: $(grep '^bind-address' /etc/mysql/mysql.conf.d/mysqld.cnf)" || \
    echo "    bind-address not explicitly set — defaults to 127.0.0.1, this is fine"

systemctl restart mysql

echo "==> MySQL root authenticates via unix_socket — log in with: sudo mysql (no password)."
echo "==> For services/panels that require password auth, create a separate user:"
echo '    mysql -e "CREATE USER '"'"'sqladmin'"'"'@'"'"'localhost'"'"' IDENTIFIED WITH caching_sha2_password BY '"'"'YOUR_PASSWORD'"'"'; GRANT ALL PRIVILEGES ON *.* TO '"'"'sqladmin'"'"'@'"'"'localhost'"'"' WITH GRANT OPTION; FLUSH PRIVILEGES;"'

echo "==> Configuring Nginx default site (drop IP traffic)..."
cat > /etc/nginx/sites-available/default <<EOF
server {
    listen 80 default_server;
    listen [::]:80 default_server;
    server_name _;
    return 444; # non-standard Nginx status: close the connection with no HTTP response
    # Instantly drops the TCP connection with no response at all,
    # before any request processing happens. For bots/scanners hitting
    # the server directly by IP (not by domain name), this is noticeably
    # cheaper in CPU/file-access terms under high junk traffic volume,
    # and it doesn't leak the nginx signature via the default page.
}
EOF

echo "==> Configuring system metrics server (Nginx stub_status & dynamic PHP-FPM status)..."
cat > /etc/nginx/conf.d/metrics.conf <<'EOF'
server {
    # Listen only on localhost
    listen 127.0.0.1:80;
    server_name 127.0.0.1;

    # Nginx native status
    location = /nginx_status {
        stub_status;
        allow 127.0.0.1;
        deny all;
    }

    # Status for the default "www" pool
    # curl http://127.0.0.1/status/www
    location = /status/www {
        allow 127.0.0.1;
        deny all;
        include fastcgi_params;
        
        fastcgi_param SCRIPT_NAME /status;
        fastcgi_param SCRIPT_FILENAME /status;
        
        fastcgi_pass unix:/run/php/php8.5-fpm.sock;
    }

    # Dynamic PHP-FPM status for isolated pools
    # Access via: curl http://127.0.0.1/status/pool_name
    location ~ ^/status/(?<pool>.+)$ {
        allow 127.0.0.1;
        deny all;
        include fastcgi_params;
        
        fastcgi_param SCRIPT_NAME /status;
        fastcgi_param SCRIPT_FILENAME /status;
        
        fastcgi_pass unix:/run/php/php8.5-fpm-$pool.sock;
    }
}
EOF

echo "==> Enabling PHP-FPM status page for default www pool..."
sed -i 's/^;pm.status_path = \/status/pm.status_path = \/status/' /etc/php/8.5/fpm/pool.d/www.conf

echo "==> Restarting services..."
nginx -t && systemctl restart nginx
systemctl restart php8.5-fpm

echo "==> Server initialization complete."