make service-check / make service: the service layer through the Makefile #31

Closed
opened 2026-10-06 15:01:14 +00:00 by pit · 0 comments
Owner

Parent

#27

What to build

make service-check runs the playbook in check mode with diffs, and make service runs it for real, both against the correct inventory; both refuse when the Vault password file is absent. The service layer is the only one with no OpenTofu state, so its gate is the check run rather than a plan artifact. The runbook's "the Makefile" section gains this Target's entry.

Acceptance criteria

  • make service-check runs the playbook in check mode with diffs and mutates nothing.
  • make service runs against the Prod inventory.
  • A missing Vault password file fails the Target before the playbook starts.
  • The runbook documents this Target.

Blocked by

  • ##29 — the Makefile scaffold and its apply gate.
## Parent #27 ## What to build `make service-check` runs the playbook in check mode with diffs, and `make service` runs it for real, both against the correct inventory; both refuse when the Vault password file is absent. The service layer is the only one with no OpenTofu state, so its gate is the check run rather than a plan artifact. The runbook's "the Makefile" section gains this Target's entry. ## Acceptance criteria - [ ] `make service-check` runs the playbook in check mode with diffs and mutates nothing. - [ ] `make service` runs against the Prod inventory. - [ ] A missing Vault password file fails the Target before the playbook starts. - [ ] The runbook documents this Target. ## Blocked by - ##29 — the Makefile scaffold and its apply gate.
pit closed this issue 2026-10-06 15:52:50 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
olympus/infra-forge#31
No description provided.