Add deployment pin-drift check (make verify-pin)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-16 10:46:26 +02:00
parent 28539bfce2
commit a69adb6498
4 changed files with 194 additions and 4 deletions

View file

@ -4,13 +4,14 @@ PIP ?= $(PYTHON) -m pip
PYTEST ?= $(PYTHON) -m pytest
RUFF ?= $(VENV)/bin/ruff
.PHONY: help install-dev test lint run
.PHONY: help install-dev test lint run verify-pin
help:
@echo "make install-dev Create .venv and install runtime + dev dependencies"
@echo "make test Run the test suite"
@echo "make lint Run syntax and static checks"
@echo "make run Start the local API on 127.0.0.1:8090"
@echo "make verify-pin Check production against the repo's pinned digest"
$(VENV)/bin/python:
python3 -m venv $(VENV)
@ -31,3 +32,8 @@ lint: $(VENV)/.dev-installed
run: $(VENV)/.dev-installed
$(PYTHON) -m tenant_engine.main
# Needs cluster access. tenant-engine runs on railiance01:
# KUBECONFIG=~/.kube/config-railiance01 make verify-pin
verify-pin:
@./deploy/verify-pin.sh