Skip to content

Commit f0660b9

Browse files
authored
chore(make): drop broken recipes, pin dev tools, add ci to .PHONY (#1245)
Fixes review findings HYG-05 and HYG-11: - Remove the cost-estimate (Makefile) and profile-new (Makefile.terraform) targets: they invoke scripts/cost-estimate.sh and scripts/generate-profile.sh, which never existed in repo history, so both targets fail immediately. Drop their help lines and the stale references in docs/DEVELOPMENT.md and terraform/profiles/README.md. - Add ci to .PHONY so a file named "ci" cannot mask the target. - Pin install-dev-tools to the CI versions instead of @latest: golangci-lint v2.10.1 (v2 module path), gosec v2.22.4, gocyclo v0.6.0, golang-migrate v4.19.1. staticcheck has no CI pin and is only used by scripts/security-scan.sh; pinned to v0.7.0. - Point "not installed" hints at make install-dev-tools instead of per-tool @latest go install commands. The docker-compose v1 part of HYG-11 was already fixed on main by 5f45f5c (ci: use docker compose v2 instead of docker-compose v1). Verified with make -n on every touched target in both Makefiles and go list -m on each pinned module version. Closes #1174, Closes #1181
1 parent e899c61 commit f0660b9

4 files changed

Lines changed: 26 additions & 71 deletions

File tree

‎Makefile‎

Lines changed: 24 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,22 @@
22
test-coverage full-test security-scan terraform-validate docker-build \
33
fmt vet lint complexity complexity-report security-scan-go security-scan-docker \
44
security-scan-terraform terraform-fmt terraform-fmt-check iac-arm docker-test pre-commit \
5-
setup-git-secrets security-scan-snyk security-scan-all cost-estimate docker-compose-test \
5+
setup-git-secrets security-scan-snyk security-scan-all ci docker-compose-test \
66
install-dev-tools
77

88
# Variables
99
VERSION?=dev
1010
BUILD_TIME?=$(shell date -u '+%Y-%m-%dT%H:%M:%SZ')
1111
GIT_SHA?=$(shell git rev-parse --short HEAD 2>/dev/null || echo unknown)
12+
13+
# Dev tool versions - keep in sync with the CI pins in
14+
# .github/workflows/ci.yml, pre-commit.yml and database-migration.yml
15+
GOLANGCI_LINT_VERSION?=v2.10.1
16+
GOSEC_VERSION?=v2.22.4
17+
GOCYCLO_VERSION?=v0.6.0
18+
MIGRATE_VERSION?=v4.19.1
19+
# staticcheck has no CI pin; it is used by scripts/security-scan.sh
20+
STATICCHECK_VERSION?=v0.7.0
1221
LDFLAGS=-ldflags "-s -w -X main.Version=$(VERSION) -X main.BuildTime=$(BUILD_TIME) -X main.GitSHA=$(GIT_SHA)"
1322

1423
# Default target
@@ -32,7 +41,6 @@ help: ## Display available targets
3241
@echo " security-scan-all - Run all security scanners including Snyk"
3342
@echo " setup-git-secrets - Set up git-secrets for preventing credential leaks"
3443
@echo " terraform-validate - Validate Terraform configurations"
35-
@echo " cost-estimate - Estimate infrastructure costs with Infracost"
3644
@echo " docker-build - Build Docker image"
3745
@echo " docker-compose-test - Run E2E tests with docker-compose"
3846
@echo " ci - Run CI pipeline locally"
@@ -94,7 +102,7 @@ lint:
94102
@if command -v golangci-lint > /dev/null; then \
95103
golangci-lint run --timeout=5m; \
96104
else \
97-
echo "golangci-lint not installed. Install: go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest"; \
105+
echo "golangci-lint not installed. Install: make install-dev-tools"; \
98106
fi
99107

100108
# Go vet
@@ -117,7 +125,7 @@ complexity:
117125
echo "✅ All functions have acceptable cyclomatic complexity (≤10)"; \
118126
fi \
119127
else \
120-
echo "gocyclo not installed. Install: go install github.com/fzipp/gocyclo/cmd/gocyclo@latest"; \
128+
echo "gocyclo not installed. Install: make install-dev-tools"; \
121129
exit 1; \
122130
fi
123131

@@ -129,7 +137,7 @@ complexity-report:
129137
echo ""; \
130138
echo "📊 Top 20 most complex functions saved to: complexity-report.txt"; \
131139
else \
132-
echo "gocyclo not installed. Install: go install github.com/fzipp/gocyclo/cmd/gocyclo@latest"; \
140+
echo "gocyclo not installed. Install: make install-dev-tools"; \
133141
fi
134142

135143
# Security scanning
@@ -141,7 +149,7 @@ security-scan-go:
141149
gosec -fmt=json -out=gosec-report.json -exclude=G101,G104,G115,G204,G301,G304,G402,G505 ./...; \
142150
echo "✓ Go security scan complete: gosec-report.json"; \
143151
else \
144-
echo "gosec not installed. Install: go install github.com/securego/gosec/v2/cmd/gosec@latest"; \
152+
echo "gosec not installed. Install: make install-dev-tools"; \
145153
fi
146154

147155
security-scan-docker:
@@ -221,11 +229,6 @@ security-scan-snyk:
221229
security-scan-all: security-scan security-scan-snyk
222230
@echo "✓ All security scans complete"
223231

224-
# Cost estimation with Infracost
225-
cost-estimate:
226-
@echo "Estimating infrastructure costs..."
227-
@bash scripts/cost-estimate.sh
228-
229232
# Docker Compose E2E tests
230233
docker-compose-test:
231234
@echo "Running E2E tests with docker-compose..."
@@ -235,22 +238,21 @@ docker-compose-test:
235238
# Install development dependencies
236239
install-dev-tools:
237240
@echo "Installing development tools..."
238-
@echo "Installing golangci-lint..."
239-
@go install github.com/golangci/golangci-lint/cmd/golangci-lint@latest
240-
@echo "Installing gosec..."
241-
@go install github.com/securego/gosec/v2/cmd/gosec@latest
242-
@echo "Installing staticcheck..."
243-
@go install honnef.co/go/tools/cmd/staticcheck@latest
244-
@echo "Installing gocyclo..."
245-
@go install github.com/fzipp/gocyclo/cmd/gocyclo@latest
246-
@echo "Installing golang-migrate..."
247-
@go install -tags 'postgres' github.com/golang-migrate/migrate/v4/cmd/migrate@latest
241+
@echo "Installing golangci-lint $(GOLANGCI_LINT_VERSION)..."
242+
@go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@$(GOLANGCI_LINT_VERSION)
243+
@echo "Installing gosec $(GOSEC_VERSION)..."
244+
@go install github.com/securego/gosec/v2/cmd/gosec@$(GOSEC_VERSION)
245+
@echo "Installing staticcheck $(STATICCHECK_VERSION)..."
246+
@go install honnef.co/go/tools/cmd/staticcheck@$(STATICCHECK_VERSION)
247+
@echo "Installing gocyclo $(GOCYCLO_VERSION)..."
248+
@go install github.com/fzipp/gocyclo/cmd/gocyclo@$(GOCYCLO_VERSION)
249+
@echo "Installing golang-migrate $(MIGRATE_VERSION)..."
250+
@go install -tags 'postgres' github.com/golang-migrate/migrate/v4/cmd/migrate@$(MIGRATE_VERSION)
248251
@echo "✓ Development tools installed"
249252
@echo ""
250253
@echo "Additional tools to install manually:"
251254
@echo " - trivy: https://aquasecurity.github.io/trivy/"
252255
@echo " - tfsec: https://aquasecurity.github.io/tfsec/"
253-
@echo " - infracost: https://www.infracost.io/docs/"
254256
@echo " - git-secrets: https://github.com/awslabs/git-secrets"
255257
@echo " - snyk: npm install -g snyk"
256258
@echo " - pre-commit: pip install pre-commit"

‎Makefile.terraform‎

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# Terraform Deployment Makefile
22
# Simplified commands for common Terraform operations
33

4-
.PHONY: help deploy plan destroy profile-new profile-list profile-show clean clean-locks \
4+
.PHONY: help deploy plan destroy profile-list profile-show clean clean-locks \
55
output aws-dev aws-prod azure-dev gcp-dev quick-plan aws-dev-plan quick-deploy \
66
validate fmt state-list state-show docker-build docker-skip frontend-only frontend-skip
77

@@ -24,7 +24,6 @@ help: ## Show this help message
2424
@echo " make plan PROFILE=prod # Plan AWS prod deployment"
2525
@echo ""
2626
@echo "Profile Management:"
27-
@echo " make profile-new # Create new profile interactively"
2827
@echo " make profile-list # List all available profiles"
2928
@echo " make profile-show # Show current profile contents"
3029
@echo ""
@@ -54,9 +53,6 @@ destroy: ## Destroy infrastructure (asks for confirmation)
5453
output: ## Show Terraform outputs
5554
@./scripts/tf-deploy.sh $(PROVIDER) $(PROFILE) output
5655

57-
profile-new: ## Create new profile interactively
58-
@./scripts/generate-profile.sh
59-
6056
profile-list: ## List all available profiles
6157
@echo "Available Profiles:"
6258
@echo "━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━"

‎docs/DEVELOPMENT.md‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -321,7 +321,6 @@ make security-scan-terraform # tfsec
321321
make terraform-validate
322322
make terraform-fmt-check
323323
make terraform-fmt
324-
make cost-estimate # requires infracost
325324

326325
make docker-build # build Docker image
327326
make docker-test # build and test image

‎terraform/profiles/README.md‎

Lines changed: 1 addition & 43 deletions
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ terraform apply -var-file="../../../profiles/aws/prod.tfvars"
5757

5858
## Creating a New Profile
5959

60-
### Option 1: Copy from Example
60+
### Copy from Example
6161

6262
```bash
6363
# Copy example profile
@@ -70,22 +70,6 @@ vim profiles/aws/my-profile.tfvars
7070
terraform apply -var-file="../../../profiles/aws/my-profile.tfvars"
7171
```
7272

73-
### Option 2: Use Profile Generator
74-
75-
```bash
76-
# Generate new profile interactively
77-
./scripts/generate-profile.sh
78-
79-
# Prompts for:
80-
# - Cloud provider (aws/azure/gcp)
81-
# - Environment name
82-
# - Region
83-
# - Compute platform
84-
# - Other settings
85-
86-
# Creates: profiles/{provider}/{name}.tfvars
87-
```
88-
8973
## Profile Contents
9074

9175
Each profile contains environment-specific variables:
@@ -382,32 +366,6 @@ terraform init
382366
terraform $ACTION -var-file="../../../../${PROFILE_FILE}"
383367
```
384368

385-
### generate-profile.sh
386-
387-
```bash
388-
#!/bin/bash
389-
# Interactive profile generator
390-
391-
echo "Creating new Terraform profile..."
392-
read -p "Cloud provider (aws/azure/gcp): " provider
393-
read -p "Profile name: " profile_name
394-
read -p "Region: " region
395-
read -p "Compute platform: " compute_platform
396-
397-
cat > "profiles/${provider}/${profile_name}.tfvars" <<EOF
398-
# Auto-generated profile
399-
provider = "${provider}"
400-
environment = "${profile_name}"
401-
region = "${region}"
402-
compute_platform = "${compute_platform}"
403-
project_name = "cudly"
404-
405-
# Add more settings as needed
406-
EOF
407-
408-
echo "✅ Profile created: profiles/${provider}/${profile_name}.tfvars"
409-
```
410-
411369
## Related Documentation
412370

413371
- [Docker Build Module](../modules/build/README.md)

0 commit comments

Comments
 (0)