make verify: the external checks as a Target (#33) #41
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!41
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/33-make-verify"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
make verifynow runs the external checks that establish a deploy actuallyworked, against Prod, seen from the WAN. It reports each check's result, mutates
nothing, and exits non-zero if any fails.
Host and repo are pinned as
VERIFY_*variables, so the checks name thedeployed site rather than a hand-typed URL. Runbook 0001 gains a "Verifying —
make verify" section and now calls outverifyas a read-only Target safe torun at will.
The
0 changedidempotence check stays a documented manual second run: bakingit in would double a service-touching Prod run.
Closes #33
Evidence
Before: "it deployed" rested on the playbook exiting zero, and the checks
were prose in the runbook.
After —
make verify, live against Prod:Failure path —
make verify VERIFY_HOST=example.invalidreports FAIL for allfour checks and exits non-zero.
~/.ssh/known_hostsis byte-identical beforeand after the run (the clone uses a throwaway
UserKnownHostsFile).make -n verifycomposes the recipe;make fmtexits 0.Merge Danger
Door: two-way — one Target and its runbook entry; revert the commit.
Blast Radius: none on the estate.
verifyis read-only, and merging the PRdoes not run it.
`make verify` runs the external checks that establish a deploy actually worked, against Prod, from the WAN, and reports each one's result: - https answers 200; http answers 301 to the https host (the Location is checked, not just the code); - an SSH clone works from the WAN (a real clone, into a temp dir, leaving the Operator's known_hosts alone); - the host the instance advertises is the *.thepit.space one, so the clone URLs the UI builds are WAN-published and not LAN-reachable. The Target mutates nothing — no estate change, no local known_hosts write — and exits non-zero if any check fails. Host and repo are pinned as VERIFY_* variables so the checks name the deployed site rather than a hand-typed URL. The `0 changed` idempotence check stays a documented manual second run, as before: baking it in would double a service-touching Prod run. Runbook 0001 gains a "Verifying — make verify" section, marks verify a read-only Target safe to run at will, and points section 5 at it.