|
|
@@ -7,6 +7,9 @@
|
|
|
|
# run_platform.sh --plan-only <contract.yml> (AWS plan only, no Checkov/outbox)
|
|
|
|
# run_platform.sh --plan-only <contract.yml> (AWS plan only, no Checkov/outbox)
|
|
|
|
# run_platform.sh --apply <contract.yml> (AWS apply: init/validate/plan/apply)
|
|
|
|
# run_platform.sh --apply <contract.yml> (AWS apply: init/validate/plan/apply)
|
|
|
|
# run_platform.sh --destroy <contract.yml> (AWS destroy: init/validate/destroy)
|
|
|
|
# run_platform.sh --destroy <contract.yml> (AWS destroy: init/validate/destroy)
|
|
|
|
|
|
|
|
# run_platform.sh --local [contract.yml] (local emulating tier, no AWS)
|
|
|
|
|
|
|
|
# run_platform.sh --decommission <CR> <contract.yml> (gated teardown)
|
|
|
|
|
|
|
|
# run_platform.sh --help (show all flags)
|
|
|
|
#
|
|
|
|
#
|
|
|
|
# Modes:
|
|
|
|
# Modes:
|
|
|
|
# --check-only (offline, no AWS/Checkov/DynamoDB — for CI)
|
|
|
|
# --check-only (offline, no AWS/Checkov/DynamoDB — for CI)
|
|
|
@@ -17,6 +20,8 @@
|
|
|
|
# contract -> resolver -> stack -> adapter -> terraform init/validate/plan/apply -> exit 0
|
|
|
|
# contract -> resolver -> stack -> adapter -> terraform init/validate/plan/apply -> exit 0
|
|
|
|
# --destroy (requires AWS creds; use --decommission <CR> for gated production teardown)
|
|
|
|
# --destroy (requires AWS creds; use --decommission <CR> for gated production teardown)
|
|
|
|
# contract -> resolver -> stack -> adapter -> terraform init/validate/destroy -> exit 0
|
|
|
|
# contract -> resolver -> stack -> adapter -> terraform init/validate/destroy -> exit 0
|
|
|
|
|
|
|
|
# --local (no AWS creds; local emulating tier D-092)
|
|
|
|
|
|
|
|
# contract -> resolver -> adapter -> local S3/ECS/outbox/Lambda stubs -> exit 0
|
|
|
|
# (default) (requires AWS creds + Checkov + DynamoDB)
|
|
|
|
# (default) (requires AWS creds + Checkov + DynamoDB)
|
|
|
|
# contract -> resolver -> stack -> adapter -> terraform plan -> Checkov ->
|
|
|
|
# contract -> resolver -> stack -> adapter -> terraform plan -> Checkov ->
|
|
|
|
# confidence -> outbox
|
|
|
|
# confidence -> outbox
|
|
|
@@ -24,6 +29,10 @@
|
|
|
|
# Flags:
|
|
|
|
# Flags:
|
|
|
|
# --quiet suppress terraform/checkov streaming (output to log only)
|
|
|
|
# --quiet suppress terraform/checkov streaming (output to log only)
|
|
|
|
# --decommission gate --destroy with D-070 two-step CR validation (requires <CR>)
|
|
|
|
# --decommission gate --destroy with D-070 two-step CR validation (requires <CR>)
|
|
|
|
|
|
|
|
# --deploy-uptime deploy the uptime monitoring stack (separate state)
|
|
|
|
|
|
|
|
# --local run the headline E2E against the local emulating tier (D-092)
|
|
|
|
|
|
|
|
# --environment <name> override the contract's environment at load time (D-088)
|
|
|
|
|
|
|
|
# --help, -h show all flags + a one-line description
|
|
|
|
#
|
|
|
|
#
|
|
|
|
# The contract file is a YAML file validated against schemas/contract.schema.json.
|
|
|
|
# The contract file is a YAML file validated against schemas/contract.schema.json.
|
|
|
|
# The resolver (core/contract_resolver.py) resolves it to a Target Stack
|
|
|
|
# The resolver (core/contract_resolver.py) resolves it to a Target Stack
|
|
|
@@ -59,6 +68,36 @@ CHANGE_REQUEST_ID=""
|
|
|
|
ENVIRONMENT_OVERRIDE=""
|
|
|
|
ENVIRONMENT_OVERRIDE=""
|
|
|
|
CONTRACT=""
|
|
|
|
CONTRACT=""
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# P15 (REQ-179): --help / -h prints all flags + a one-line description.
|
|
|
|
|
|
|
|
_print_help() {
|
|
|
|
|
|
|
|
cat <<'HELP'
|
|
|
|
|
|
|
|
Nova platform pipeline — run_platform.sh
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Usage:
|
|
|
|
|
|
|
|
run_platform.sh <contract.yml> (full e2e with AWS)
|
|
|
|
|
|
|
|
run_platform.sh --check-only [contract.yml] (offline, no AWS)
|
|
|
|
|
|
|
|
run_platform.sh --plan-only <contract.yml> (AWS plan only)
|
|
|
|
|
|
|
|
run_platform.sh --apply <contract.yml> (AWS apply)
|
|
|
|
|
|
|
|
run_platform.sh --destroy <contract.yml> (AWS destroy)
|
|
|
|
|
|
|
|
run_platform.sh --local [contract.yml] (local emulating tier)
|
|
|
|
|
|
|
|
run_platform.sh --decommission <CR> <contract.yml> (gated teardown)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Flags:
|
|
|
|
|
|
|
|
--check-only Offline validation (no AWS/Checkov/DynamoDB) — for CI
|
|
|
|
|
|
|
|
--plan-only AWS plan only (requires AWS creds, no Checkov/outbox)
|
|
|
|
|
|
|
|
--apply AWS apply: init/validate/plan/apply (HITL gate for qa/prod/dr)
|
|
|
|
|
|
|
|
--destroy AWS destroy: init/validate/destroy
|
|
|
|
|
|
|
|
--decommission Gate --destroy with D-070 two-step CR validation (requires <CR>)
|
|
|
|
|
|
|
|
--local Run the headline E2E against the local emulating tier (D-092, no AWS)
|
|
|
|
|
|
|
|
--quiet Suppress terraform/checkov streaming (log only)
|
|
|
|
|
|
|
|
--deploy-uptime Deploy the uptime monitoring stack (separate state)
|
|
|
|
|
|
|
|
--environment <name> Override the contract's environment at load time (D-088)
|
|
|
|
|
|
|
|
--help, -h Show this help
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The contract file is a YAML file validated against schemas/contract.schema.json.
|
|
|
|
|
|
|
|
HELP
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
# Parse args; --environment takes a value (either --environment=VALUE or
|
|
|
|
# Parse args; --environment takes a value (either --environment=VALUE or
|
|
|
|
# --environment VALUE). The contract / changeRequestId are the remaining
|
|
|
|
# --environment VALUE). The contract / changeRequestId are the remaining
|
|
|
|
# positional args.
|
|
|
|
# positional args.
|
|
|
@@ -69,6 +108,7 @@ for arg in "$@"; do
|
|
|
|
continue
|
|
|
|
continue
|
|
|
|
fi
|
|
|
|
fi
|
|
|
|
case "$arg" in
|
|
|
|
case "$arg" in
|
|
|
|
|
|
|
|
--help|-h) _print_help; exit 0 ;;
|
|
|
|
--check-only) CHECK_ONLY=1 ;;
|
|
|
|
--check-only) CHECK_ONLY=1 ;;
|
|
|
|
--plan-only) PLAN_ONLY=1 ;;
|
|
|
|
--plan-only) PLAN_ONLY=1 ;;
|
|
|
|
--apply) APPLY_ONLY=1 ;;
|
|
|
|
--apply) APPLY_ONLY=1 ;;
|
|
|
|