TEN-WP-0002 T01-T03: service skeleton, domain model, storage layer
Python 3.12 + FastAPI, pyproject.toml + Makefile mirroring
qonto-assistant's exactly. src/tenant_engine/{domain,store,app,main}.py:
- domain.py: Tenant, CapabilityRole (PLTF/IAM/VEN/CUS), RoleGrant,
PlanAssignment, create_role_grant() enforcing ADR-0014's invariants.
Refinement made while implementing: platform_default grants are valid
for trial-grouped tenants OR the reserved tenant:platform/tenant:coulomb
tenants (their baseline roles were never purchased either) -- the task
spec only named the trial case.
- store.py: TenantStore Protocol + InMemoryTenantStore, every mutation
emits a DomainEvent per the boundary contract's Audit Correlation
Contract.
- app.py/main.py: FastAPI factory + /health endpoint, verified live on
127.0.0.1:8090.
29 tests passing, including non-exclusive role coexistence (CUS+VEN
simultaneously) and append-only revoke semantics.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 22:01:23 +02:00
|
|
|
VENV ?= .venv
|
|
|
|
|
PYTHON ?= $(VENV)/bin/python
|
|
|
|
|
PIP ?= $(PYTHON) -m pip
|
|
|
|
|
PYTEST ?= $(PYTHON) -m pytest
|
|
|
|
|
RUFF ?= $(VENV)/bin/ruff
|
|
|
|
|
|
2026-08-29 14:51:27 +02:00
|
|
|
.PHONY: help install-dev test lint run verify-pin validate-app-toml
|
TEN-WP-0002 T01-T03: service skeleton, domain model, storage layer
Python 3.12 + FastAPI, pyproject.toml + Makefile mirroring
qonto-assistant's exactly. src/tenant_engine/{domain,store,app,main}.py:
- domain.py: Tenant, CapabilityRole (PLTF/IAM/VEN/CUS), RoleGrant,
PlanAssignment, create_role_grant() enforcing ADR-0014's invariants.
Refinement made while implementing: platform_default grants are valid
for trial-grouped tenants OR the reserved tenant:platform/tenant:coulomb
tenants (their baseline roles were never purchased either) -- the task
spec only named the trial case.
- store.py: TenantStore Protocol + InMemoryTenantStore, every mutation
emits a DomainEvent per the boundary contract's Audit Correlation
Contract.
- app.py/main.py: FastAPI factory + /health endpoint, verified live on
127.0.0.1:8090.
29 tests passing, including non-exclusive role coexistence (CUS+VEN
simultaneously) and append-only revoke semantics.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 22:01:23 +02:00
|
|
|
|
|
|
|
|
help:
|
|
|
|
|
@echo "make install-dev Create .venv and install runtime + dev dependencies"
|
|
|
|
|
@echo "make test Run the test suite"
|
|
|
|
|
@echo "make lint Run syntax and static checks"
|
|
|
|
|
@echo "make run Start the local API on 127.0.0.1:8090"
|
2026-08-29 14:51:27 +02:00
|
|
|
@echo "make verify-pin Check production against the repo's pinned digest"
|
|
|
|
|
@echo "make validate-app-toml Validate railiance/app.toml against railiance.app.v1"
|
TEN-WP-0002 T01-T03: service skeleton, domain model, storage layer
Python 3.12 + FastAPI, pyproject.toml + Makefile mirroring
qonto-assistant's exactly. src/tenant_engine/{domain,store,app,main}.py:
- domain.py: Tenant, CapabilityRole (PLTF/IAM/VEN/CUS), RoleGrant,
PlanAssignment, create_role_grant() enforcing ADR-0014's invariants.
Refinement made while implementing: platform_default grants are valid
for trial-grouped tenants OR the reserved tenant:platform/tenant:coulomb
tenants (their baseline roles were never purchased either) -- the task
spec only named the trial case.
- store.py: TenantStore Protocol + InMemoryTenantStore, every mutation
emits a DomainEvent per the boundary contract's Audit Correlation
Contract.
- app.py/main.py: FastAPI factory + /health endpoint, verified live on
127.0.0.1:8090.
29 tests passing, including non-exclusive role coexistence (CUS+VEN
simultaneously) and append-only revoke semantics.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 22:01:23 +02:00
|
|
|
|
|
|
|
|
$(VENV)/bin/python:
|
|
|
|
|
python3 -m venv $(VENV)
|
|
|
|
|
|
|
|
|
|
$(VENV)/.dev-installed: pyproject.toml $(VENV)/bin/python
|
|
|
|
|
$(PIP) install --upgrade pip
|
|
|
|
|
$(PIP) install -e ".[dev]"
|
|
|
|
|
@touch $(VENV)/.dev-installed
|
|
|
|
|
|
|
|
|
|
install-dev: $(VENV)/.dev-installed
|
|
|
|
|
|
|
|
|
|
test: $(VENV)/.dev-installed
|
|
|
|
|
$(PYTEST)
|
|
|
|
|
|
|
|
|
|
lint: $(VENV)/.dev-installed
|
|
|
|
|
$(PYTHON) -m compileall src tests
|
|
|
|
|
$(RUFF) check src tests
|
|
|
|
|
|
|
|
|
|
run: $(VENV)/.dev-installed
|
|
|
|
|
$(PYTHON) -m tenant_engine.main
|
2026-08-16 10:46:26 +02:00
|
|
|
|
|
|
|
|
# Needs cluster access. tenant-engine runs on railiance01:
|
|
|
|
|
# KUBECONFIG=~/.kube/config-railiance01 make verify-pin
|
2026-08-29 14:51:27 +02:00
|
|
|
validate-app-toml: $(VENV)/.dev-installed
|
|
|
|
|
$(PYTHON) tests/validate_app_toml.py
|
|
|
|
|
|
2026-08-16 10:46:26 +02:00
|
|
|
verify-pin:
|
|
|
|
|
@./deploy/verify-pin.sh
|