feat: adopt security zones and explicit workload refs
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0291a-1e87-7151-9934-fcbfe3f65eb1
This commit is contained in:
tegwick 2026-08-22 15:36:37 +02:00
parent 12c637cbf2
commit 7ce58ae638
52 changed files with 1547 additions and 658 deletions

View file

@ -136,8 +136,13 @@ def main() -> int:
if args.check:
current = args.out.read_text() if args.out.exists() else ""
# generated_at always differs; compare everything else.
strip = lambda t: "\n".join(l for l in t.splitlines() if not l.startswith("generated_at:"))
if strip(current) != strip(content):
def strip_generated_at(text: str) -> str:
return "\n".join(
line for line in text.splitlines()
if not line.startswith("generated_at:")
)
if strip_generated_at(current) != strip_generated_at(content):
print(f"STALE: {args.out} does not match the catalog. Re-run without --check.")
return 1
print(f"fresh: {args.out} matches the catalog ({count} concrete paths)")