The Makefile: help, the apply gate, and the Guest Stack as the first Target #29
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Blocks
#32 make snapshot and make state-backup: the pre-flight and post-flight gates
olympus/infra-forge
#33 make verify: the external checks as a Target
olympus/infra-forge
#30 make edge-plan / make edge: the Edge Stack through the Makefile
olympus/infra-forge
#31 make service-check / make service: the service layer through the Makefile
olympus/infra-forge
#35 make pre and make pre-down: the PRE rehearsal
olympus/infra-forge
Reference
olympus/infra-forge#29
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent
#27
What to build
The Makefile exists at the repo root and is the packaged form of the procedure, so the Operator or an Agent runs a named Target instead of reconstructing the sequence from a runbook. A bare
makeandmake helplist the Targets and deploy nothing.make guest-planandmake guestrun the Guest Stack end to end: initialise, source the layer's own.env, plan to a saved artifact, render that artifact for review, ask for confirmation by typing the environment's word, then apply the artifact that was reviewed. A missing secret file stops the Target before any mutating command is composed.make fmt,make validateandmake sshround out the scaffold.This is the tracer bullet: the interface, the apply gate, and the first real layer, with the documentation for exactly what it adds. The runbook gains its "the Makefile" section here — the section intro and the description of the gate — and the glossary gains the Target term.
Acceptance criteria
makeandmake helplist the Targets; neither deploys.make guest-planshows a full plan and mutates nothing.make guestrenders the plan, applies the artifact that was reviewed, and applies nothing unless the environment word is typed..envis sourced by the Target, not by the caller.tofu initruns before plan and before apply.make fmt,make validateandmake sshwork.make -non any Target composes and prints the command without executing it.Blocked by
pit referenced this issue2026-10-06 15:24:56 +00:00
Closed manually: PR #38 merged into
mainas0591359, but the PR body saidRefs #29rather thanCloses #29, so Forgejo did not auto-close this issue.Verified on merged
mainbefore closing:Makefilepresent and byte-identical to the reviewed branch.make/make helplist the Targets and deploy nothing.make guest-planshows the plan and mutates nothing.make guestcomposes init → plan -out=plan.out → tofu show plan.out →prodgate → apply plan.out.tofu/.envfails before any command is composed.make -ncomposes without executing;make fmt/make validatepass against real OpenTofu.main.All acceptance criteria met.