Onboard tenant-engine to the staged-promotion contract
All checks were successful
Build and Publish Container Image / build-and-push (push) Successful in 50s

TEN-WP-0008. railiance/app.toml declares criticality=high, empty secrets,
isolated canary, and the live PostgreSQL digest as previous_stable.
Manifests render through kustomize (deploy/ and deploy/canary/). Stage 1
passed. Stage 2/3 Helm-only CLI gap requested as RAIL-BS-IN-0001 rather
than a dummy chart.

Assistant: grok
Assistant-Session: 01a04cea-e5e8-7081-a0fc-808ebbc35fa9
This commit is contained in:
tegwick 2026-08-29 14:51:27 +02:00
parent f9f8e0c54f
commit 6644ad8402
19 changed files with 1053 additions and 18 deletions

View file

@ -4,14 +4,15 @@ PIP ?= $(PYTHON) -m pip
PYTEST ?= $(PYTHON) -m pytest
RUFF ?= $(VENV)/bin/ruff
.PHONY: help install-dev test lint run verify-pin
.PHONY: help install-dev test lint run verify-pin validate-app-toml
help:
@echo "make install-dev Create .venv and install runtime + dev dependencies"
@echo "make test Run the test suite"
@echo "make lint Run syntax and static checks"
@echo "make run Start the local API on 127.0.0.1:8090"
@echo "make verify-pin Check production against the repo's pinned digest"
@echo "make verify-pin Check production against the repo's pinned digest"
@echo "make validate-app-toml Validate railiance/app.toml against railiance.app.v1"
$(VENV)/bin/python:
python3 -m venv $(VENV)
@ -35,5 +36,8 @@ run: $(VENV)/.dev-installed
# Needs cluster access. tenant-engine runs on railiance01:
# KUBECONFIG=~/.kube/config-railiance01 make verify-pin
validate-app-toml: $(VENV)/.dev-installed
$(PYTHON) tests/validate_app_toml.py
verify-pin:
@./deploy/verify-pin.sh