make verify: the external checks as a Target (#33) #41

Merged
pit merged 2 commits from hermes/33-make-verify into main 2026-10-06 15:56:33 +00:00
Owner

Summary

make verify now runs the external checks that establish a deploy actually
worked, against Prod, seen from the WAN. It reports each check's result, mutates
nothing, and exits non-zero if any fails.

make verify
  https GET        → 200
  http GET         → 301 to the https host (the Location is checked)
  git clone (SSH)  → succeeds, into a temp dir with a throwaway known_hosts
  advertised host  → https://forgejo.thepit.space/, so the clone URLs the UI
                     builds are WAN-published, not LAN-reachable

Host and repo are pinned as VERIFY_* variables, so the checks name the
deployed site rather than a hand-typed URL. Runbook 0001 gains a "Verifying —
make verify" section and now calls out verify as a read-only Target safe to
run at will.

The 0 changed idempotence check stays a documented manual second run: baking
it in would double a service-touching Prod run.

Closes #33

Evidence

Before: "it deployed" rested on the playbook exiting zero, and the checks
were prose in the runbook.

After — make verify, live against Prod:

verify: the external checks, seen from the WAN.

  ok    https://forgejo.thepit.space answers 200
  ok    http://forgejo.thepit.space answers 301 to https://forgejo.thepit.space/
  ok    SSH clone works from the WAN (git@forgejo.thepit.space:pit/infra-forge.git)
  ok    the instance advertises the right host for its clone URLs (git@forgejo.thepit.space:pit/infra-forge.git)

verify: all checks passed.

Failure path — make verify VERIFY_HOST=example.invalid reports FAIL for all
four checks and exits non-zero. ~/.ssh/known_hosts is byte-identical before
and after the run (the clone uses a throwaway UserKnownHostsFile). make -n verify composes the recipe; make fmt exits 0.

Merge Danger

Door: two-way — one Target and its runbook entry; revert the commit.

Blast Radius: none on the estate. verify is read-only, and merging the PR
does not run it.

## Summary `make verify` now runs the external checks that establish a deploy actually worked, against Prod, seen from the WAN. It reports each check's result, mutates nothing, and exits non-zero if any fails. ```text make verify https GET → 200 http GET → 301 to the https host (the Location is checked) git clone (SSH) → succeeds, into a temp dir with a throwaway known_hosts advertised host → https://forgejo.thepit.space/, so the clone URLs the UI builds are WAN-published, not LAN-reachable ``` Host and repo are pinned as `VERIFY_*` variables, so the checks name the deployed site rather than a hand-typed URL. Runbook 0001 gains a "Verifying — `make verify`" section and now calls out `verify` as a read-only Target safe to run at will. The `0 changed` idempotence check stays a documented manual second run: baking it in would double a service-touching Prod run. Closes #33 ## Evidence **Before:** "it deployed" rested on the playbook exiting zero, and the checks were prose in the runbook. **After** — `make verify`, live against Prod: ```text verify: the external checks, seen from the WAN. ok https://forgejo.thepit.space answers 200 ok http://forgejo.thepit.space answers 301 to https://forgejo.thepit.space/ ok SSH clone works from the WAN (git@forgejo.thepit.space:pit/infra-forge.git) ok the instance advertises the right host for its clone URLs (git@forgejo.thepit.space:pit/infra-forge.git) verify: all checks passed. ``` Failure path — `make verify VERIFY_HOST=example.invalid` reports FAIL for all four checks and exits non-zero. `~/.ssh/known_hosts` is byte-identical before and after the run (the clone uses a throwaway `UserKnownHostsFile`). `make -n verify` composes the recipe; `make fmt` exits 0. ## Merge Danger **Door:** two-way — one Target and its runbook entry; revert the commit. **Blast Radius:** none on the estate. `verify` is read-only, and merging the PR does not run it.
`make verify` runs the external checks that establish a deploy actually
worked, against Prod, from the WAN, and reports each one's result:

  - https answers 200; http answers 301 to the https host (the Location is
    checked, not just the code);
  - an SSH clone works from the WAN (a real clone, into a temp dir, leaving
    the Operator's known_hosts alone);
  - the host the instance advertises is the *.thepit.space one, so the clone
    URLs the UI builds are WAN-published and not LAN-reachable.

The Target mutates nothing — no estate change, no local known_hosts write —
and exits non-zero if any check fails. Host and repo are pinned as VERIFY_*
variables so the checks name the deployed site rather than a hand-typed URL.

The `0 changed` idempotence check stays a documented manual second run, as
before: baking it in would double a service-touching Prod run.

Runbook 0001 gains a "Verifying — make verify" section, marks verify a
read-only Target safe to run at will, and points section 5 at it.
main gained the Edge Stack (#30) and the service layer (#31) Targets, which
touch the same Makefile and runbook hunks as `verify`. Both sides kept:

- Makefile: main's shared `confirm_and_apply` / `service_rehearsal` gate
  defines, the Edge and service Targets, and this branch's `verify` Target;
  `.PHONY` merged to list every target (help guest-plan guest verify edge-plan
  edge fmt validate ssh service-check service).
- runbook: the read-only Target list gains `verify` alongside main's
  `edge-plan` / `service-check`; the Edge, service and Verifying sections all
  stand, in the order Guest → Edge → service → verify.

Verified after the merge: `make help` lists all targets, `make -n` composes
every one with no unresolved variables, `make fmt` exits 0, and `make verify`
passes live against Prod.
pit merged commit 25ae3860d8 into main 2026-10-06 15:56:33 +00:00
pit deleted branch hermes/33-make-verify 2026-10-06 15:56:33 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
olympus/infra-forge!41
No description provided.