verify(P9): run-platform-split — 4-layer verify PASS + ship
VERIFY: structural — 2 helpers extracted (sourced, G-112); behavioral — CI PASS + regression gate 18V+4S PASS (G-111, D-118); quality — run_platform.sh ~80 lines smaller. ---ci--- project: acdl phase: 9 milestone: v1.16 status: complete phase_role: execution requirements: covered: [REQ-173] partial: [] ---/ci---
This commit is contained in:
+6
-142
@@ -208,63 +208,10 @@ jsonschema.validate(contract, schema)
|
||||
print(f'contract: id={contract[\"id\"]} env={contract[\"environment\"]} modules={list(contract.get(\"infrastructure\",{}).keys())}')
|
||||
"
|
||||
|
||||
# Decommission mode: validate change request, disable deletion protection, zero counts
|
||||
# Decommission mode: extracted to scripts/run_decommission.sh (P9, REQ-173).
|
||||
# G-112: sourced (shared env) — the block references CONTRACT/WORK/ROOT.
|
||||
if [ "$DECOMMISSION" = "1" ]; then
|
||||
echo ""
|
||||
echo "=== Decommission Step 1: validate change request against CMDB ==="
|
||||
[ -n "$CHANGE_REQUEST_ID" ] || fail "change request ID required for decommission mode"
|
||||
CONSUMER_REPO="${GITHUB_REPOSITORY:-$(python3 -c "import yaml; c=yaml.safe_load(open('$CONTRACT')); print(c.get('id','unknown'))" 2>/dev/null || echo 'unknown')}"
|
||||
python3 -c "
|
||||
import json, sys
|
||||
sys.path.insert(0, '$ROOT')
|
||||
# In a real deployment, this invokes the Lambda. For local/CI, we simulate.
|
||||
cr_id = '$CHANGE_REQUEST_ID'
|
||||
repo = '$CONSUMER_REPO'
|
||||
print(f'validate_change_request: crId={cr_id} repo={repo}')
|
||||
# The Lambda action would be:
|
||||
# payload = {'action': 'validate_change_request', 'changeRequestId': cr_id, 'consumerRepo': repo}
|
||||
# result = invoke_lambda(payload)
|
||||
# For now, just print the intent (the actual validation happens via the Lambda in CI/prod)
|
||||
print('change request validation: PASS (simulated for local mode)')
|
||||
"
|
||||
echo ""
|
||||
echo "=== Decommission Step 2: disable deletion protection (HITL SRE gate) ==="
|
||||
echo "This step requires SRE approval via GitHub environment 'decommission-gate-sre'."
|
||||
echo "The contract is resolved with deletion_protection=false injected."
|
||||
python3 core/contract_resolver.py "$CONTRACT" "$WORK/stack.json" 2>/dev/null || fail "resolver failed"
|
||||
python3 -c "
|
||||
import json, sys
|
||||
sys.path.insert(0, '$ROOT')
|
||||
from core.contract_resolver import resolve, decommission_transform
|
||||
stack = resolve('$CONTRACT', '$ROOT')
|
||||
# Step 2: disable deletion protection only (counts still as-is)
|
||||
for res in stack['resources']:
|
||||
if 'nfrs' not in res:
|
||||
res['nfrs'] = {}
|
||||
res['nfrs']['deletion_protection'] = False
|
||||
with open('$WORK/stack-decommission-step1.json', 'w') as f:
|
||||
json.dump(stack, f, indent=2)
|
||||
print(f'decommission step 1: {len(stack[\"resources\"])} resources with deletion_protection=false')
|
||||
"
|
||||
echo ""
|
||||
echo "=== Decommission Step 3: zero counts (HITL SRE gate) ==="
|
||||
echo "This step requires a second SRE approval via GitHub environment 'decommission-destroy-sre'."
|
||||
python3 -c "
|
||||
import json, sys
|
||||
sys.path.insert(0, '$ROOT')
|
||||
from core.contract_resolver import resolve, decommission_transform
|
||||
stack = resolve('$CONTRACT', '$ROOT')
|
||||
stack = decommission_transform(stack)
|
||||
with open('$WORK/stack-decommission-step2.json', 'w') as f:
|
||||
json.dump(stack, f, indent=2)
|
||||
zeroed = sum(1 for r in stack['resources'] if r.get('nfrs',{}).get('deletion_protection') is False)
|
||||
print(f'decommission step 2: {zeroed} resources with deletion_protection=false + counts=0')
|
||||
"
|
||||
echo ""
|
||||
echo "=== Decommission Step 4: confirm ==="
|
||||
echo "The terraform apply for step 2 + step 3 would now destroy all resources."
|
||||
echo "=== DECOMMISSION READY ==="
|
||||
exit 0
|
||||
source "$ROOT/scripts/run_decommission.sh"
|
||||
fi
|
||||
|
||||
echo ""
|
||||
@@ -501,92 +448,9 @@ PY
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "=== Step 9b: deploy uptime monitoring (separate state) ==="
|
||||
# The uptime stack is deployed by default after the L2 module. It uses a
|
||||
# separate terraform state ($WORK/uptime-tf). Endpoints from the L2 outputs
|
||||
# are passed as monitored_endpoints. The feature flag (uptime_enabled,
|
||||
# default true) controls whether this step runs.
|
||||
#
|
||||
# P57 contract shape: uptime_enabled is a per-module input under
|
||||
# infrastructure.<module>.inputs.uptime_enabled (the old top-level
|
||||
# contract.inputs.uptime_enabled was removed). Scan every module's inputs;
|
||||
# any module setting uptime_enabled=false disables the uptime step (one
|
||||
# contract = one logical stack, so a single false wins).
|
||||
if [ "$DEPLOY_UPTIME" = "1" ] || ( [ "$CHECK_ONLY" = "0" ] && [ "$PLAN_ONLY" = "0" ] ); then
|
||||
UPTIME_ENABLED=$(python3 -c "
|
||||
import yaml
|
||||
c = yaml.safe_load(open('$CONTRACT'))
|
||||
infra = c.get('infrastructure', {})
|
||||
# Default true; a module may override to false.
|
||||
for m, entry in infra.items():
|
||||
if isinstance(entry, dict) and entry.get('inputs', {}).get('uptime_enabled') is False:
|
||||
print('False'); break
|
||||
else:
|
||||
print('True')
|
||||
" 2>/dev/null || echo "True")
|
||||
if [ "$UPTIME_ENABLED" = "True" ] || [ "$UPTIME_ENABLED" = "true" ]; then
|
||||
echo "uptime: feature flag enabled — constructing uptime contract"
|
||||
UPTIME_DIR="$WORK/uptime-tf"
|
||||
mkdir -p "$UPTIME_DIR"
|
||||
# Build the uptime stack from the L2 outputs
|
||||
python3 "$ROOT/core/contract_resolver.py" "$CONTRACT" "$WORK/stack.json" 2>/dev/null || true
|
||||
python3 -c "
|
||||
import json, sys, yaml
|
||||
sys.path.insert(0, '$ROOT')
|
||||
from core.contract_resolver import resolve
|
||||
stack = resolve('$CONTRACT', '$ROOT')
|
||||
# Extract HTTP/DNS/TCP endpoints from the stack outputs
|
||||
endpoints = []
|
||||
outputs = stack.get('outputs', {})
|
||||
for name, spec in outputs.items():
|
||||
src_rid = spec.get('from', '')
|
||||
src_output = spec.get('output', name)
|
||||
if 'domain' in name.lower() or 'url' in name.lower() or 'endpoint' in name.lower():
|
||||
endpoints.append({
|
||||
'name': name,
|
||||
'url': f'ref:{src_rid}.{src_output}',
|
||||
'type': 'http',
|
||||
'interval_seconds': 60,
|
||||
'timeout_seconds': 30
|
||||
})
|
||||
# Build the uptime contract
|
||||
uptime_contract = {
|
||||
'id': 'uptime',
|
||||
'name': 'uptime-monitoring',
|
||||
'environment': 'dev',
|
||||
'infrastructure': {
|
||||
'uptime': {
|
||||
'version': '1.0.0',
|
||||
'inputs': {
|
||||
'region': 'us-east-1',
|
||||
'feature_flag_enabled': True,
|
||||
'monitored_endpoints': endpoints,
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
with open('$WORK/uptime-contract.yml', 'w') as f:
|
||||
yaml.dump(uptime_contract, f)
|
||||
print(f'uptime: {len(endpoints)} endpoint(s) to monitor')
|
||||
" 2>/dev/null || echo "uptime: no endpoints found (skipping monitor config)"
|
||||
|
||||
# Resolve + adapt the uptime contract to a separate TF dir
|
||||
python3 "$ROOT/core/contract_resolver.py" "$WORK/uptime-contract.yml" "$WORK/uptime-stack.json" 2>/dev/null || true
|
||||
python3 "$ROOT/adapters/terraform/adapter.py" "$WORK/uptime-stack.json" "$UPTIME_DIR" 2>/dev/null || true
|
||||
|
||||
if [ "$DEPLOY_UPTIME" = "1" ] && [ -f "$UPTIME_DIR/main.tf" ]; then
|
||||
echo "uptime: emitted Terraform to $UPTIME_DIR"
|
||||
if [ "$QUIET" = "0" ]; then
|
||||
echo "--- uptime main.tf ---"
|
||||
cat "$UPTIME_DIR/main.tf"
|
||||
echo "--- end uptime main.tf ---"
|
||||
fi
|
||||
fi
|
||||
echo "uptime: monitoring stack ready (separate state: $UPTIME_DIR)"
|
||||
else
|
||||
echo "uptime: feature flag disabled (inputs.uptime_enabled=false) — skipping"
|
||||
fi
|
||||
fi
|
||||
# Uptime monitoring: extracted to scripts/run_uptime.sh (P9, REQ-173).
|
||||
# G-112: sourced (shared env) — the block references CONTRACT/WORK/DEPLOY_UPTIME.
|
||||
source "$ROOT/scripts/run_uptime.sh"
|
||||
|
||||
echo ""
|
||||
echo "=== PLATFORM E2E OK ==="
|
||||
|
||||
Reference in New Issue
Block a user