#!/usr/bin/env bash
# Run on the offline RHEL host. Installs files only; no services or network access.
set -euo pipefail
root="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)"
prefix="${1:-/opt/devsecops}"
[[ "$(uname -m)" == x86_64 ]] || { echo 'This bundle requires x86_64' >&2; exit 1; }
. /etc/os-release
[[ "$ID" == rhel && "$VERSION_ID" == 9.6 ]] || { echo 'Expected RHEL 9.6; validate a different OS separately' >&2; exit 1; }
[[ "$prefix" == /* && "$prefix" != / && ! -e "$prefix" ]] || { echo 'Choose a new absolute installation directory' >&2; exit 1; }
cd "$root"
sha256sum --check SHA256SUMS
for tool in bash python3 git tar; do command -v "$tool" >/dev/null; done
mkdir -p "$prefix"
cp -a bin scripts examples "$prefix/"
mkdir -p "$prefix/cache"
cp -a cache/trivy cache/grype "$prefix/cache/"
chmod -R a+rX "$prefix/cache/grype"
echo "Installed to $prefix. Add $prefix/bin to PATH."
echo 'Give each scanner job its own writable cache copy; see INSTALL-OFFLINE.md.'
echo 'Load the ZAP image separately as the account that will run ZAP.'
