Command and execution scope
Run repository commands from its root unless a command explicitly names another directory. The table identifies default scope; it does not replace the prerequisites and stop conditions in the linked operator guide. A plan validates intent. Source validation tests contracts. Live execution needs observations before it becomes evidence.
Source and local commands
Section titled “Source and local commands”| Command | Scope and effects | Guide/source |
|---|---|---|
PYTHON=.venv/bin/python make validate |
Credential-free source checks; renders configuration, initializes Terraform with backend disabled, runs tests. First use may download dependencies. | Source validation, validate.sh |
python3 scripts/validate-docs.py |
Offline local documentation, screenshot hash/inventory, and vector-generation check. | Presentation validator |
make test |
Ordinary pytest suite; default configuration excludes the integration marker. | Makefile, pytest.ini |
make local-up |
Builds and starts unpaid local Compose services. | Local development |
make smoke-local |
Creates/redirects a URL, checks health while Redis is stopped, restores Redis, then removes Compose containers and volumes. | smoke-local.sh |
make local-down |
Removes the Compose project, volumes, and orphan containers. | Compose definition |
make config |
Copies example operator configuration only when the ignored local file is absent. It does not provision a lab. | Configuration example |
make render-config |
Writes public configuration into reviewable tracked manifests. Review its diff before a separate operational change. | Renderer |
The documentation site’s own commands live in the site README. They build static content and assets from an explicit allowlist; they are independent of cloud bootstrap and live lab state.
Plans, read-only inspection, and live requests
Section titled “Plans, read-only inspection, and live requests”| Entrypoint/default | Execution scope | Relevant guide |
|---|---|---|
scripts/lab-ops.sh status |
Read-only exact-context verifier; --scope platform|gitops|gate|all. No Secret data inspection. |
Lab lifecycle |
scripts/lab-ops.sh bootstrap-plan |
Dry-run bootstrap review; no apply. Operational prerequisites may require cloud access. | Bootstrap phases |
scripts/lab-ops.sh destroy-plan |
Refreshes remote Terraform state and calculates a destroy plan with normal locking; no deletion. | Lab lifecycle |
scripts/lab-ops.sh destroy |
Requires apply flag, exact project, owned-testnet acknowledgement, TTY, and project retype. Applies a newly saved destroy plan. | Lifecycle source |
scripts/run-loadgen.sh --plan |
No-network plan; default paid staging scenario. --execute creates one bounded Job. |
Load testing |
scripts/run-loadgen.sh --plan --scenario baseline |
No-network plan for unpaid dev GET /; execute reuses suspended staging source template, copies summary, and verifies exact Job cleanup. |
Load runner |
scripts/validate-live.sh --plan --scenario NAME |
No-network Kargo plan. Execute requests current-Freight re-verification or named-Freight promotion. | Promotion |
scripts/collect-evidence.sh --plan |
No-network collection plan with required scenario/status/run ID. --collect reads scoped objects and writes a sanitized local bundle. |
Evidence publication |
scripts/score-baseline.py |
Queries a supplied credential-free Prometheus endpoint and optionally writes a bounded scorecard. No Job or promotion. | Baseline scorer |
scripts/test-payment-flow.sh |
Refuses execution without explicit RUN_TESTNET_PAYMENTS=1; can perform real testnet settlement. Never ordinary CI. |
Payment runbook |
baseline has two meanings in different commands: live validation requests the dev Stage’s service-health contract; load generation produces bounded unpaid traffic against dev. Neither implicitly runs the other.
Named staging promotion needs --acknowledge-staging-promotion; named prod-like promotion needs --acknowledge-prod-promotion. Both also require --acknowledge-owned-testnet-lab, execute mode, and exact-context validation. A successful request exit means acceptance only. Observe the resulting AnalysisRun and applicable scores/cleanup separately.
Evidence utility
Section titled “Evidence utility”Validate a public retained metadata record without contacting a lab:
python3 scripts/evidence_utils.py validate \ --metadata docs/evidence/healthy-chaos/20261001-staging-gate-b8cc5caa/run-metadata.json \ --schema schemas/run-metadata.schema.jsonThe utility also provides sanitize, write-metadata, and extract-scorecard. Extraction recovers one complete named chaos scorecard from an already-sanitized gate log; it does not synthesize a missing verdict. See format reference and utility source before creating a new record.
All plans and read-only inspections remain distinct from mutating bootstrap phases. Do not use convenience Make targets to infer permission to apply Terraform, spend tokens, promote Freight, or destroy resources.
Maintained by Satyam Agnihotri · DevOps & Cloud Engineer