make edge-plan / make edge: the Edge Stack through the Makefile (#30) #39

Merged
pit merged 1 commit from hermes/30-make-edge into main 2026-10-06 15:49:47 +00:00
Owner

What this does

Implements #30: make edge-plan and make edge run the Edge Stack (tofu/npm/) through the Makefile, so its two required arguments cannot be forgotten.

  • Both Targets source tofu/npm/.env themselves (the NPM provider credentials) and pass -var-file=forgejo.tfvars automatically — no caller-supplied source or -var-file.
  • make edge runs the same three-step apply gate as make guest: plan to plan.out → render with tofu show → confirm by typing prod → apply that artifact.
  • make edge-plan shows the full plan and mutates nothing.
  • A missing tofu/npm/.env refuses before any command is composed.
 Makefile
   .PHONY: help guest-plan guest edge-plan edge fmt validate ssh
+  EDGE_DIR      := tofu/npm
+  EDGE_VAR_FILE := forgejo.tfvars
+  define confirm_and_apply     # the gate tail, shared by Guest and Edge
+     tofu show plan.out → type the word → tofu apply plan.out
+
+  edge-plan:   cd tofu/npm; source .env; tofu init; tofu plan -var-file=forgejo.tfvars
+  edge:        … tofu plan -out=plan.out -var-file=forgejo.tfvars; confirm_and_apply prod

 docs/runbooks/0001-deploy-and-rollback.md
+  ### The Edge Stack            (edge-plan / edge table + the var-file rationale)
   ### The apply gate           (word now stated for both Stacks)
   read-only Targets            (guest-plan, edge-plan)

The guest Target's gate was factored into the shared confirm_and_apply macro and rewired to call it. Its composed command line is byte-identical before and after (make -n guest diffed).

Verification

  • make -n edge-plan / make -n edge compose cd tofu/npm → source .env → tofu init → tofu plan [-out=plan.out] -var-file=forgejo.tfvars → render → typed word → apply; both .env and -var-file come from the Target.
  • make edge against the unchanged estate: No changes. Your infrastructure matches the configuration. → Apply complete! Resources: 0 added, 0 changed, 0 destroyed. Run against a copy of the state, so the live state file's mtime is unchanged.
  • Abort path: typing anything but prod prints applying nothing, removes plan.out, exits non-zero.
  • make fmt leaves the tree unmodified; make validate succeeds; make / make help list all eight Targets and deploy nothing.

Merge Danger

Door: two-way — reverting the commit removes two Targets and restores the runbook section; nothing in the estate changes.

Blast Radius: low — additive Makefile Targets plus docs. Only latent effect: guest now routes its gate through the shared macro (behaviour identical).

Review

Two-axis /code-review (Standards + Spec) ran on the diff: no functional defects, no documented-standard violations. Acted on its judgement calls — deduped the runbook's var-file rationale to point at §3, and documented the shared plan.out relative-path/cwd coupling in the macro comment. The $(1) environment-word parameter and the Target-preamble duplication were left as-is (the pre/pre-down Targets need a second word; the two Stacks' paths differ).

Sibling Targets (service, snapshot, state-backup, verify, prod, pre) stay out of scope — #31–#35.

Refs #30.

## What this does Implements #30: `make edge-plan` and `make edge` run the Edge Stack (`tofu/npm/`) through the Makefile, so its two required arguments cannot be forgotten. - Both Targets source `tofu/npm/.env` themselves (the NPM provider credentials) and pass `-var-file=forgejo.tfvars` automatically — no caller-supplied `source` or `-var-file`. - `make edge` runs the same three-step apply gate as `make guest`: plan to `plan.out` → render with `tofu show` → confirm by typing `prod` → apply *that* artifact. - `make edge-plan` shows the full plan and mutates nothing. - A missing `tofu/npm/.env` refuses before any command is composed. ```diff Makefile .PHONY: help guest-plan guest edge-plan edge fmt validate ssh + EDGE_DIR := tofu/npm + EDGE_VAR_FILE := forgejo.tfvars + define confirm_and_apply # the gate tail, shared by Guest and Edge + tofu show plan.out → type the word → tofu apply plan.out + + edge-plan: cd tofu/npm; source .env; tofu init; tofu plan -var-file=forgejo.tfvars + edge: … tofu plan -out=plan.out -var-file=forgejo.tfvars; confirm_and_apply prod docs/runbooks/0001-deploy-and-rollback.md + ### The Edge Stack (edge-plan / edge table + the var-file rationale) ### The apply gate (word now stated for both Stacks) read-only Targets (guest-plan, edge-plan) ``` The `guest` Target's gate was factored into the shared `confirm_and_apply` macro and rewired to call it. Its composed command line is byte-identical before and after (`make -n guest` diffed). ## Verification - `make -n edge-plan` / `make -n edge` compose `cd tofu/npm` → `source .env` → `tofu init` → `tofu plan [-out=plan.out] -var-file=forgejo.tfvars` → render → typed word → apply; both `.env` and `-var-file` come from the Target. - `make edge` against the unchanged estate: `No changes. Your infrastructure matches the configuration.` → `Apply complete! Resources: 0 added, 0 changed, 0 destroyed.` Run against a copy of the state, so the live state file's mtime is unchanged. - Abort path: typing anything but `prod` prints `applying nothing`, removes `plan.out`, exits non-zero. - `make fmt` leaves the tree unmodified; `make validate` succeeds; `make` / `make help` list all eight Targets and deploy nothing. ## Merge Danger **Door:** two-way — reverting the commit removes two Targets and restores the runbook section; nothing in the estate changes. **Blast Radius:** low — additive Makefile Targets plus docs. Only latent effect: `guest` now routes its gate through the shared macro (behaviour identical). ## Review Two-axis `/code-review` (Standards + Spec) ran on the diff: no functional defects, no documented-standard violations. Acted on its judgement calls — deduped the runbook's var-file rationale to point at §3, and documented the shared `plan.out` relative-path/cwd coupling in the macro comment. The `$(1)` environment-word parameter and the Target-preamble duplication were left as-is (the `pre`/`pre-down` Targets need a second word; the two Stacks' paths differ). Sibling Targets (`service`, `snapshot`, `state-backup`, `verify`, `prod`, `pre`) stay out of scope — #31–#35. Refs #30.
make edge-plan and make edge run the Edge Stack through the same gate as the
Guest Target: they source tofu/npm/.env themselves, pass the mandatory
-var-file automatically, and apply the plan artifact that was reviewed after the
environment word is typed. The runbook's Makefile section gains the Edge Stack
entry.

Closes #30
pit merged commit ef029c53ba into main 2026-10-06 15:49:47 +00:00
pit deleted branch hermes/30-make-edge 2026-10-06 15:49:47 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
olympus/infra-forge!39
No description provided.