Repository scripts
scripts/ ⧉ holds tooling for the repository itself. Almost
all of it is invoked by pre-commit ⧉ or CI
rather than by hand.
| Script | Invoked by | Purpose |
|---|---|---|
lint-commit-message |
pre-commit, commit-msg stage |
Enforces the [tag] Imperative subject convention and the tag allowlist |
sops-merge-driver |
git | Merges SOPS files without mac/lastmodified conflicts |
sops-check-decryptable |
pre-commit | Verifies encrypted inventory files can be decrypted |
sops-find-unencrypted-secrets |
pre-commit | Flags sensitive inventory keys left in the clear |
renovate-fix-config |
pre-commit | Auto-fixes renovate.json validation errors |
generate-workload-secrets.bash |
by hand, per environment | Fills a workload inventory's generatable secrets, then sops-encrypts it |
gen-imports.py |
by hand, after a plan | Turns a unit's plan JSON into neph terragrunt ... import commands |
api_calls_for_monitoring.py |
API Monitoring workflow |
Probes the public API |
slack_monitoring_messager.py |
CI | Posts monitoring results to Slack |
Commit message tags
lint-commit-message accepts only a fixed set of tags, e.g. [iris], [gateway], [infra]. A new component therefore
needs its tag added to the allowlist in the script before anyone can commit to it.
See VCS etiquette for what the messages themselves should say.
The SOPS merge driver
Git does not use the driver until you register it once per clone:
git config --local include.path ../.gitconfig
Without this, merging two branches that both touched an encrypted inventory file conflicts on the mac and
lastmodified metadata rather than on the contents.