"""Validate deployment invariants without emitting rendered secrets."""
import json, subprocess, sys

def config(args):
    result = subprocess.run(['docker', 'compose', *args, 'config', '--format', 'json'], capture_output=True, text=True)
    if result.returncode: raise RuntimeError('Compose validation failed; check required settings privately')
    return json.loads(result.stdout)['services']
production = config(['--env-file', sys.argv[1], '-f', 'docker-compose.production.yml'])
for name in ['postgres', 'redis', 'clamav']:
    assert not production[name].get('ports'), name
for name in ['api', 'migrate', 'ranking-worker', 'data-import-worker', 'verification-worker', 'sitemap-worker']:
    service = production[name]
    assert service['environment']['NODE_ENV'] == 'production', name
    assert service['build']['target'] == 'production', name
    assert 'seed' not in str(service.get('command', '')), name
for name in ['api', 'web', 'admin']:
    assert all(p.get('host_ip') == '127.0.0.1' for p in production[name]['ports']), name
assert production['web']['environment']['NEXT_PUBLIC_DEMO_MODE'] == 'false'
local = config(['-f', 'docker-compose.yml', '-f', 'docker-compose.local.yml'])
for name, port in [('api', '4002'), ('web', '3002'), ('admin', '3003')]:
    assert str(local[name]['ports'][0]['published']) == port, name
assert local['api']['environment']['API_PUBLIC_URL'] == 'http://localhost:4002'
assert local['web']['build']['args']['NEXT_PUBLIC_ADMIN_URL'] == 'http://localhost:3003'
assert 'seed' not in str(local['migrate']['command'])
print('PASS production isolation/migration-only/nonroot image targets; local ports and build URLs')
