Skip to content

Command and execution scope

Run repository commands from its root unless a command explicitly names another directory. The table identifies default scope; it does not replace the prerequisites and stop conditions in the linked operator guide. A plan validates intent. Source validation tests contracts. Live execution needs observations before it becomes evidence.

Command Scope and effects Guide/source
PYTHON=.venv/bin/python make validate Credential-free source checks; renders configuration, initializes Terraform with backend disabled, runs tests. First use may download dependencies. Source validation, validate.sh
python3 scripts/validate-docs.py Offline local documentation, screenshot hash/inventory, and vector-generation check. Presentation validator
make test Ordinary pytest suite; default configuration excludes the integration marker. Makefile, pytest.ini
make local-up Builds and starts unpaid local Compose services. Local development
make smoke-local Creates/redirects a URL, checks health while Redis is stopped, restores Redis, then removes Compose containers and volumes. smoke-local.sh
make local-down Removes the Compose project, volumes, and orphan containers. Compose definition
make config Copies example operator configuration only when the ignored local file is absent. It does not provision a lab. Configuration example
make render-config Writes public configuration into reviewable tracked manifests. Review its diff before a separate operational change. Renderer

The documentation site’s own commands live in the site README. They build static content and assets from an explicit allowlist; they are independent of cloud bootstrap and live lab state.

Plans, read-only inspection, and live requests

Section titled “Plans, read-only inspection, and live requests”
Entrypoint/default Execution scope Relevant guide
scripts/lab-ops.sh status Read-only exact-context verifier; --scope platform|gitops|gate|all. No Secret data inspection. Lab lifecycle
scripts/lab-ops.sh bootstrap-plan Dry-run bootstrap review; no apply. Operational prerequisites may require cloud access. Bootstrap phases
scripts/lab-ops.sh destroy-plan Refreshes remote Terraform state and calculates a destroy plan with normal locking; no deletion. Lab lifecycle
scripts/lab-ops.sh destroy Requires apply flag, exact project, owned-testnet acknowledgement, TTY, and project retype. Applies a newly saved destroy plan. Lifecycle source
scripts/run-loadgen.sh --plan No-network plan; default paid staging scenario. --execute creates one bounded Job. Load testing
scripts/run-loadgen.sh --plan --scenario baseline No-network plan for unpaid dev GET /; execute reuses suspended staging source template, copies summary, and verifies exact Job cleanup. Load runner
scripts/validate-live.sh --plan --scenario NAME No-network Kargo plan. Execute requests current-Freight re-verification or named-Freight promotion. Promotion
scripts/collect-evidence.sh --plan No-network collection plan with required scenario/status/run ID. --collect reads scoped objects and writes a sanitized local bundle. Evidence publication
scripts/score-baseline.py Queries a supplied credential-free Prometheus endpoint and optionally writes a bounded scorecard. No Job or promotion. Baseline scorer
scripts/test-payment-flow.sh Refuses execution without explicit RUN_TESTNET_PAYMENTS=1; can perform real testnet settlement. Never ordinary CI. Payment runbook

baseline has two meanings in different commands: live validation requests the dev Stage’s service-health contract; load generation produces bounded unpaid traffic against dev. Neither implicitly runs the other.

Named staging promotion needs --acknowledge-staging-promotion; named prod-like promotion needs --acknowledge-prod-promotion. Both also require --acknowledge-owned-testnet-lab, execute mode, and exact-context validation. A successful request exit means acceptance only. Observe the resulting AnalysisRun and applicable scores/cleanup separately.

Validate a public retained metadata record without contacting a lab:

Terminal window
python3 scripts/evidence_utils.py validate \
--metadata docs/evidence/healthy-chaos/20261001-staging-gate-b8cc5caa/run-metadata.json \
--schema schemas/run-metadata.schema.json

The utility also provides sanitize, write-metadata, and extract-scorecard. Extraction recovers one complete named chaos scorecard from an already-sanitized gate log; it does not synthesize a missing verdict. See format reference and utility source before creating a new record.

All plans and read-only inspections remain distinct from mutating bootstrap phases. Do not use convenience Make targets to infer permission to apply Terraform, spend tokens, promote Freight, or destroy resources.

Maintained by Satyam Agnihotri · DevOps & Cloud Engineer