krply/Makefile
lakshit verma 9f4b6c2c5a
fix(audit,web,deploy): audit ids, web dry-run view, hardened chart, docs
Audit: correlation event_ids include stage and response code so the
multi-stage lines of one request no longer collapse under dedup; match
scans are bounded to a time window and a page instead of the object's full
history.

Web: dry-run results are read from dry_run_result (nested) so the verdict is
rendered correctly and conflicts/errors/skipped are shown; the plans view no
longer POSTs an unsolicited plan on page load; coverage and streams surface
API errors instead of showing a misleading empty state and follow cursor
pagination so they are not stuck on the oldest page; the diff path tokenizer
handles backslash-escaped dotted keys.

Deploy/CI: the chart no longer grants the query server a cluster-wide read
ClusterRole, runs as non-root with a read-only root filesystem, adds
liveness/readiness probes, wires the ConfigMap as env (STORE_PATH,
LISTEN_ADDR), defaults the journal to a PVC instead of an ephemeral
emptyDir, and adds imagePullSecrets; the replay ClusterRole drops the
unused update verb; a Dockerfile builds a static distroless image; GitHub
actions are pinned by commit SHA, jobs set least-privilege permissions, the
Vercel deploy skips fork PRs, CI passes the Makefile test timeouts, and
make lint runs a real web syntax check.

Docs: event-schema/consistency no longer describe an ingest_sequence field,
an observed-time-based event_id, or restart-from-checkpoint; the threat
model documents the unauthenticated HTTP API surface and the chart's RBAC
change; replay-safety matches the enforced dry-run gate.
2026-08-06 06:57:11 +05:30

50 lines
1.1 KiB
Makefile

.PHONY: build build-server build-cli web test test-unit test-integration test-e2e lint vet fmt tidy install-bins docs clean
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo dev)
LDFLAGS := -X github.com/krply/krply/internal/version.Version=$(VERSION)
build: build-cli build-server
build-cli:
go build -ldflags '$(LDFLAGS)' -o bin/krply ./cmd/krply
build-server:
go build -ldflags '$(LDFLAGS)' -o bin/krply-server ./cmd/krply-server
web:
cd web && npm install && npm run build
test:
go test ./...
test-unit:
go test ./internal/... ./cmd/... -short
test-integration:
go test ./test/integration/... -tags integration -timeout 20m
test-e2e:
go test ./test/e2e/... -tags e2e -timeout 30m
lint:
go vet ./...
cd web && npm run lint
vet:
go vet ./...
fmt:
gofmt -w $$(find . -name '*.go' -not -path './vendor/*')
tidy:
go mod tidy
install-bins: build
install -m 0755 bin/krply /usr/local/bin/krply
install -m 0755 bin/krply-server /usr/local/bin/krply-server
docs:
@echo "documentation lives in docs/"
clean:
rm -rf bin web/dist