The Makefile: help, the apply gate, and the Guest Stack as the first Target (#29) #38

Merged
pit merged 1 commit from hermes/29-make-guest into main 2026-10-06 15:38:37 +00:00
Owner

What this does

Implements #29: the root Makefile — the interface, the apply gate, and the Guest Stack as the first Target. This is the tracer bullet for #27.

  • make / make help list the Targets and deploy nothing (default goal is help).
  • make guest-plan shows the full Guest Stack plan; mutates nothing.
  • make guest runs the three-step apply gate: plan to plan.out → render it with tofu show → confirm by typing prod → apply that artifact.
  • Both Guest Targets source tofu/.env themselves and run tofu init before planning/applying; a missing tofu/.env fails before any command is composed.
  • Targets are Prod-selected by -target (the Guest plus the shared base image).
  • make fmt, make validate and make ssh round out the scaffold.

Docs: the runbook gains its "the Makefile" section (section intro, the gate, the Guest and utility tables); the glossary defines Target.

Sibling Targets (edge, service, snapshot, state-backup, verify, prod, pre) are deliberately out of scope — they are #30–#35.

Verification

Each Target's composed command line was inspected via make -n and by running the real Targets against a throwaway tofu stub on PATH (never touching the estate): the target surface, the gate's ordering and its refusals (wrong word, EOF, piped yes), init before plan/apply, and that a sourced .env actually reaches tofu. make fmt and make validate pass against real OpenTofu.

Review

Two-axis /code-review (Standards + Spec) ran on the diff. The one hard finding — a broken ../GLOSSARY.md link in the new runbook section — is fixed.

Refs #29.

## What this does Implements #29: the root `Makefile` — the interface, the apply gate, and the Guest Stack as the first Target. This is the tracer bullet for #27. - `make` / `make help` list the Targets and deploy nothing (default goal is help). - `make guest-plan` shows the full Guest Stack plan; mutates nothing. - `make guest` runs the three-step apply gate: plan to `plan.out` → render it with `tofu show` → confirm by typing `prod` → apply *that* artifact. - Both Guest Targets source `tofu/.env` themselves and run `tofu init` before planning/applying; a missing `tofu/.env` fails before any command is composed. - Targets are Prod-selected by `-target` (the Guest plus the shared base image). - `make fmt`, `make validate` and `make ssh` round out the scaffold. Docs: the runbook gains its "the Makefile" section (section intro, the gate, the Guest and utility tables); the glossary defines **Target**. Sibling Targets (`edge`, `service`, `snapshot`, `state-backup`, `verify`, `prod`, `pre`) are deliberately out of scope — they are #30–#35. ## Verification Each Target's composed command line was inspected via `make -n` and by running the real Targets against a throwaway `tofu` stub on PATH (never touching the estate): the target surface, the gate's ordering and its refusals (wrong word, EOF, piped `yes`), `init` before plan/apply, and that a sourced `.env` actually reaches tofu. `make fmt` and `make validate` pass against real OpenTofu. ## Review Two-axis `/code-review` (Standards + Spec) ran on the diff. The one hard finding — a broken `../GLOSSARY.md` link in the new runbook section — is fixed. Refs #29.
Packages the deploy procedure as named Targets at the repo root, so the
Operator or an Agent runs `make guest` instead of reassembling the
sequence from the runbook.

- `make` / `make help` list the Targets and deploy nothing.
- `guest-plan` shows the Guest Stack plan and mutates nothing.
- `guest` runs the three-step apply gate: plan to `plan.out`, render it
  with `tofu show`, confirm by typing `prod`, then apply that artifact.
  A wrong word, EOF or a piped `yes` stops the run and applies nothing.
- Both Guest Targets source `tofu/.env` themselves and run `tofu init`
  before planning/applying; a missing `tofu/.env` fails before any
  command is composed.
- `fmt`, `validate` and `ssh` round out the scaffold. Targets are
  prod-selected by `-target` (the Guest plus the shared base image).

Docs: the runbook gains "the Makefile" section (the section intro, the
gate, the Guest and utility Tables); the glossary defines **Target**.

Tests: `tests/makefile.sh` inspects each composed command line through a
`tofu` stub on PATH — no estate contact — and covers the target surface,
the gate's ordering and refusals, and that a sourced `.env` reaches tofu.
41 assertions, all green.
pit force-pushed hermes/29-make-guest from 035926fd99 to a0f28916d8 2026-10-06 15:35:29 +00:00 Compare
pit force-pushed hermes/29-make-guest from a0f28916d8 to fccb327236 2026-10-06 15:38:25 +00:00 Compare
pit merged commit 0591359767 into main 2026-10-06 15:38:37 +00:00
pit deleted branch hermes/29-make-guest 2026-10-06 15:38:38 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
olympus/infra-forge!38
No description provided.