The Makefile: help, the apply gate, and the Guest Stack as the first Target #29

Closed
opened 2026-10-06 15:01:13 +00:00 by pit · 1 comment
Owner

Parent

#27

What to build

The Makefile exists at the repo root and is the packaged form of the procedure, so the Operator or an Agent runs a named Target instead of reconstructing the sequence from a runbook. A bare make and make help list the Targets and deploy nothing. make guest-plan and make guest run the Guest Stack end to end: initialise, source the layer's own .env, plan to a saved artifact, render that artifact for review, ask for confirmation by typing the environment's word, then apply the artifact that was reviewed. A missing secret file stops the Target before any mutating command is composed. make fmt, make validate and make ssh round out the scaffold.

This is the tracer bullet: the interface, the apply gate, and the first real layer, with the documentation for exactly what it adds. The runbook gains its "the Makefile" section here — the section intro and the description of the gate — and the glossary gains the Target term.

Acceptance criteria

  • make and make help list the Targets; neither deploys.
  • make guest-plan shows a full plan and mutates nothing.
  • make guest renders the plan, applies the artifact that was reviewed, and applies nothing unless the environment word is typed.
  • A missing secret file fails the Target before any mutating command is composed.
  • The layer's .env is sourced by the Target, not by the caller.
  • tofu init runs before plan and before apply.
  • make fmt, make validate and make ssh work.
  • The runbook's "the Makefile" section documents the gate; the glossary defines Target.
  • make -n on any Target composes and prints the command without executing it.

Blocked by

  • None (can start immediately).
## Parent #27 ## What to build The Makefile exists at the repo root and is the packaged form of the procedure, so the Operator or an Agent runs a named Target instead of reconstructing the sequence from a runbook. A bare `make` and `make help` list the Targets and deploy nothing. `make guest-plan` and `make guest` run the Guest Stack end to end: initialise, source the layer's own `.env`, plan to a saved artifact, render that artifact for review, ask for confirmation by typing the environment's word, then apply the artifact that was reviewed. A missing secret file stops the Target before any mutating command is composed. `make fmt`, `make validate` and `make ssh` round out the scaffold. This is the tracer bullet: the interface, the apply gate, and the first real layer, with the documentation for exactly what it adds. The runbook gains its "the Makefile" section here — the section intro and the description of the gate — and the glossary gains the **Target** term. ## Acceptance criteria - [x] `make` and `make help` list the Targets; neither deploys. - [x] `make guest-plan` shows a full plan and mutates nothing. - [x] `make guest` renders the plan, applies the artifact that was reviewed, and applies nothing unless the environment word is typed. - [x] A missing secret file fails the Target before any mutating command is composed. - [x] The layer's `.env` is sourced by the Target, not by the caller. - [x] `tofu init` runs before plan and before apply. - [x] `make fmt`, `make validate` and `make ssh` work. - [x] The runbook's "the Makefile" section documents the gate; the glossary defines **Target**. - [x] `make -n` on any Target composes and prints the command without executing it. ## Blocked by - None (can start immediately).
Author
Owner

Closed manually: PR #38 merged into main as 0591359, but the PR body said Refs #29 rather than Closes #29, so Forgejo did not auto-close this issue.

Verified on merged main before closing:

  • Makefile present and byte-identical to the reviewed branch.
  • make / make help list the Targets and deploy nothing.
  • make guest-plan shows the plan and mutates nothing.
  • make guest composes init → plan -out=plan.out → tofu show plan.out → prod gate → apply plan.out.
  • A missing tofu/.env fails before any command is composed.
  • make -n composes without executing; make fmt / make validate pass against real OpenTofu.
  • The runbook's "the Makefile" section and the glossary's Target term are on main.

All acceptance criteria met.

Closed manually: PR #38 merged into `main` as 0591359, but the PR body said `Refs #29` rather than `Closes #29`, so Forgejo did not auto-close this issue. Verified on merged `main` before closing: - `Makefile` present and byte-identical to the reviewed branch. - `make` / `make help` list the Targets and deploy nothing. - `make guest-plan` shows the plan and mutates nothing. - `make guest` composes init → plan -out=plan.out → tofu show plan.out → `prod` gate → apply plan.out. - A missing `tofu/.env` fails before any command is composed. - `make -n` composes without executing; `make fmt` / `make validate` pass against real OpenTofu. - The runbook's "the Makefile" section and the glossary's **Target** term are on `main`. All acceptance criteria met.
pit closed this issue 2026-10-06 15:39:23 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
olympus/infra-forge#29
No description provided.