make service-check / make service: the service layer through the Makefile (#31) #40
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!40
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/31-make-service"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #31 (part of #27).
Summary
The service layer — the Ansible role that installs Forgejo and the runner — becomes two Targets, alongside the Guest Stack Targets from #29.
The layer has no OpenTofu state, so its gate is the check run rather than a saved plan —
service-checkis that run alone,serviceis the run then the playbook for real:The check command lives in one
define(service_rehearsal), shared by both Targets, mirroring the existingrequire_secretidiom. The runbook's "the Makefile" section gains the Target table, and the read-only list gainsservice-check.One limitation, documented rather than fixed:
--check --diffis a rehearsal, not a full preview. The role mutates mostly throughansible.builtin.command(account creation, the runner registration), which Ansible skips under--check, so those changes do not appear in the diff. Fixing that means reworking the role — outside this ticket, and outside the epic's scope. The runbook says so.Evidence
Before — no such Target:
After — composes against the Prod inventory, and refuses on a missing Vault before any playbook runs:
With the Vault in place and
ansible-playbookstubbed, both Targets reach the stub with the right argv:make helpand a baremakelist all eight Targets, aligned;make fmtis clean.The check-mode limitation was confirmed against a real
--checkrun: acopytask reportschangedwith a diff, acommandtask reportsskippingwith an emptyregister.stdout.Merge Danger
Door: two-way — additive Targets and docs. Reverting the merge restores the runbook's raw-command path unchanged.
Blast Radius: none until run. The Makefile only composes commands; no OpenTofu state is read or written, and
service-checkmutates nothing. The one behaviour worth noticing isservicerunning the check pass before the apply — a deliberate reading of the epic's gate for this layer (the epic fixesmake prodas… edge → service → verify …and says the service layer's gate is the check run); drop it if you disagree and it becomes a one-line deletion.f3eb9807cbto27035d314b