audit-core/Makefile
tegwick ded432a63f
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Implement AUDIT-WP-0006 honest operational custody.
Postgres now reports custody_class=operational with a cited 30-day
recoverable window. Join ITC-CAP operations.audit at D4, publish the
interface card, and overlay user-engine tenants [*] from Git so an
ExternalSecret refresh cannot shrink it.
2026-08-16 00:24:33 +02:00

73 lines
3 KiB
Makefile

SHELL := /usr/bin/env bash
.DEFAULT_GOAL := help
AUDIT_CORE_MOCK_DIR ?= /tmp/audit-core
test: ## Run unit tests
python3 -m pytest -q
mock-audit-smoke: ## Write one non-secret smoke event to the mock audit backend
AUDIT_CORE_MOCK_DIR="$(AUDIT_CORE_MOCK_DIR)" python3 -m audit_core emit \
--source audit-core \
--action audit_core.mock_backend.smoke \
--resource "$(AUDIT_CORE_MOCK_DIR)" \
--outcome success \
--detail backend=mock-file
mock-audit-cleanup: ## Remove mock audit files older than the retention window
AUDIT_CORE_MOCK_DIR="$(AUDIT_CORE_MOCK_DIR)" python3 -m audit_core cleanup
help: ## Show this help
@awk 'BEGIN {FS = ":.*##"; printf "\nUsage:\n make \033[36m<target>\033[0m\n"} \
/^[a-zA-Z_-]+:.*?##/ { printf " \033[36m%-24s\033[0m %s\n", $$1, $$2 }' $(MAKEFILE_LIST)
.PHONY: test test-pg pg-test-up pg-test-down failure-matrix mock-audit-smoke mock-audit-cleanup \
image-build image-publish deploy-dry-run help
IMAGE_REGISTRY ?= forgejo.coulomb.social/coulomb/audit-core
GIT_COMMIT := $(shell git rev-parse HEAD)
GIT_COMMIT_SHORT := $(shell git rev-parse --short HEAD)
# railiance01 k3s API is forwarded by ops-bridge tunnel k3s-api-railiance01.
KUBECONFIG_RAILIANCE ?= $(HOME)/.kube/config-hosteurope
image-build: ## Build the immutable image, labelled with the current commit
docker build -f Containerfile \
--build-arg GIT_COMMIT=$(GIT_COMMIT) \
-t $(IMAGE_REGISTRY):$(GIT_COMMIT_SHORT) \
-t $(IMAGE_REGISTRY):$(GIT_COMMIT) \
.
image-publish: image-build ## Push the commit-tagged image to Forgejo
docker push $(IMAGE_REGISTRY):$(GIT_COMMIT_SHORT)
docker push $(IMAGE_REGISTRY):$(GIT_COMMIT)
@echo "Pin the printed digest in deploy/audit-core.yaml and deploy/migrate-job.yaml"
deploy-dry-run: ## Server-side validate the railiance01 manifests
KUBECONFIG=$(KUBECONFIG_RAILIANCE) kubectl apply --dry-run=server --validate=strict \
-f deploy/audit-core.yaml \
-f deploy/senders-scope.yaml \
-f deploy/networkpolicies.yaml \
-f deploy/clustersecretstore.yaml \
-f deploy/externalsecrets.yaml \
-f deploy/migrate-job.yaml
PG_TEST_CONTAINER ?= ac-pg-test
PG_TEST_PORT ?= 55445
PG_TEST_URL ?= postgresql://postgres:test@127.0.0.1:$(PG_TEST_PORT)/audit_core
pg-test-up: ## Start a throwaway PostgreSQL for backend conformance tests
-docker rm -f $(PG_TEST_CONTAINER) 2>/dev/null
docker run -d --name $(PG_TEST_CONTAINER) -e POSTGRES_PASSWORD=test \
-e POSTGRES_DB=audit_core -p 127.0.0.1:$(PG_TEST_PORT):5432 postgres:16-alpine
@for i in $$(seq 1 40); do \
docker exec $(PG_TEST_CONTAINER) pg_isready -U postgres >/dev/null 2>&1 && exit 0; \
sleep 1; done; echo "postgres did not become ready" >&2; exit 1
pg-test-down: ## Remove the throwaway PostgreSQL
-docker rm -f $(PG_TEST_CONTAINER)
test-pg: ## Run the suite including PostgreSQL conformance (needs pg-test-up)
AUDIT_CORE_TEST_DATABASE_URL="$(PG_TEST_URL)" python3 -m pytest -q
failure-matrix: ## Run the delivery/retry/replay failure matrix (AUDIT-WP-0005-T05)
python3 scripts/failure_matrix.py