Skip to content

Repository scripts

scripts/ ⧉ holds tooling for the repository itself. Almost all of it is invoked by pre-commit ⧉ or CI rather than by hand.

Script Invoked by Purpose
lint-commit-message pre-commit, commit-msg stage Enforces the [tag] Imperative subject convention and the tag allowlist
sops-merge-driver git Merges SOPS files without mac/lastmodified conflicts
sops-check-decryptable pre-commit Verifies encrypted inventory files can be decrypted
sops-find-unencrypted-secrets pre-commit Flags sensitive inventory keys left in the clear
renovate-fix-config pre-commit Auto-fixes renovate.json validation errors
generate-workload-secrets.bash by hand, per environment Fills a workload inventory's generatable secrets, then sops-encrypts it
gen-imports.py by hand, after a plan Turns a unit's plan JSON into neph terragrunt ... import commands
api_calls_for_monitoring.py API Monitoring workflow Probes the public API
slack_monitoring_messager.py CI Posts monitoring results to Slack

Commit message tags

lint-commit-message accepts only a fixed set of tags, e.g. [iris], [gateway], [infra]. A new component therefore needs its tag added to the allowlist in the script before anyone can commit to it. See VCS etiquette for what the messages themselves should say.

The SOPS merge driver

Git does not use the driver until you register it once per clone:

git config --local include.path ../.gitconfig

Without this, merging two branches that both touched an encrypted inventory file conflicts on the mac and lastmodified metadata rather than on the contents.