flex-auth/Makefile
tegwick 56940727bf
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Build and Publish Container Image / build-and-push (push) Successful in 57s
Finish FLEX-WP-0019 layer-model v0.7 conformance
Close the remaining PDP obligations: mechanical layer declaration check,
registry-snapshot digest in provenance, explicit allow TTL, per-input-class
freshness deadlines, and the published decision-record contract. Document
the canonical request digest as the §6.4.2 replay test.

Assistant: grok
Assistant-Session: 01a06256-fb71-7102-b3a9-27e6734257d0
2026-09-03 23:48:45 +02:00

76 lines
2.2 KiB
Makefile

BIN_DIR ?= bin
BIN := $(BIN_DIR)/flex-auth
PKG := ./...
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo 0.0.0-dev)
LDFLAGS := -X main.version=$(VERSION)
.PHONY: all build test vet lint fmt tidy sbom clean ci overlay-render overlay-dry-run verify-posture check-layer
all: vet lint test build
build:
@mkdir -p $(BIN_DIR)
go build -ldflags "$(LDFLAGS)" -o $(BIN) ./cmd/flex-auth
test: check-layer
go test -race $(PKG)
check-layer:
go run ./tools/check_layer_conformance.go
vet:
go vet $(PKG)
fmt:
gofmt -l -w .
tidy:
go mod tidy
lint:
@if command -v golangci-lint >/dev/null 2>&1; then \
golangci-lint run $(PKG); \
else \
echo "golangci-lint not installed; run: go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest"; \
echo "falling back to: go vet"; \
go vet $(PKG); \
fi
GOBIN_PATH := $(shell go env GOPATH)/bin
sbom:
@mkdir -p $(BIN_DIR)
@if command -v cyclonedx-gomod >/dev/null 2>&1; then \
cyclonedx-gomod mod -json -output $(BIN_DIR)/sbom.cdx.json .; \
echo "SBOM written to $(BIN_DIR)/sbom.cdx.json (cyclonedx-gomod)"; \
elif [ -x "$(GOBIN_PATH)/cyclonedx-gomod" ]; then \
"$(GOBIN_PATH)/cyclonedx-gomod" mod -json -output $(BIN_DIR)/sbom.cdx.json .; \
echo "SBOM written to $(BIN_DIR)/sbom.cdx.json (cyclonedx-gomod via GOPATH)"; \
elif command -v syft >/dev/null 2>&1; then \
syft . -o cyclonedx-json=$(BIN_DIR)/sbom.cdx.json; \
echo "SBOM written to $(BIN_DIR)/sbom.cdx.json (syft)"; \
else \
echo "no SBOM tool found. install one:"; \
echo " go install github.com/CycloneDX/cyclonedx-gomod/cmd/cyclonedx-gomod@latest"; \
echo " or syft: https://github.com/anchore/syft"; \
exit 1; \
fi
clean:
rm -rf $(BIN_DIR)
ci: vet lint test build overlay-render
verify-posture:
@bash tools/verify-posture.sh
overlay-render:
@tests/stage1.sh
overlay-dry-run:
@test -n "$$KUBECONFIG" || { echo "set KUBECONFIG to the railiance01 kubeconfig"; exit 1; }
@for values in values/stage2-canary.yaml values/user-engine.yaml values/tenant-engine.yaml; do \
echo "server-dry-run $$values"; \
helm template flex-auth charts/flex-auth -f "$$values" --namespace flex-auth \
| kubectl apply --dry-run=server --server-side -f -; \
done