Rebuilt with KBUILD_BUILD_USER/HOST/TIMESTAMP pinned. Without them the kernel bakes the builder's user@hostname and wall-clock build time into /proc/version, which publishes operator identity in a public artifact and makes the build unreproducible. Pinned, anyone can rebuild and diff the bytes — the only trust story available for an unsigned community kernel. The installer refuses to run on anything but a Pi 4, refuses a mismatched image/modules pair (vermagic failure means no /dev/pps0 on a kernel that otherwise boots fine — silent and miserable to debug), verifies SHA256SUMS, never touches kernel8.img, and leaves rollback as deleting one config.txt line. Boot-tested on the Pi: Stratum 1, 273 ns offset, PPS handler confirmed NOT threaded. Binaries ship as release assets, not in git.
60 lines
2.1 KiB
Makefile
60 lines
2.1 KiB
Makefile
# cuckoo-escapement docs — make targets follow the warehacking cookie-cutter.
|
|
#
|
|
# `make prod` builds the static site + brings up Caddy serving it.
|
|
# `make dev` starts the Astro dev server with HMR behind Caddy.
|
|
# `make down` stops both.
|
|
|
|
SHELL := /usr/bin/env bash
|
|
.SHELLFLAGS := -eu -o pipefail -c
|
|
.DEFAULT_GOAL := help
|
|
|
|
.PHONY: help
|
|
help: ## Show this help
|
|
@awk 'BEGIN {FS = ":.*##"} /^[a-zA-Z0-9_-]+:.*##/ {printf " \033[36m%-12s\033[0m %s\n", $$1, $$2}' $(MAKEFILE_LIST)
|
|
|
|
.PHONY: prod
|
|
prod: ## Build + run the production docs container (Caddy serves dist/)
|
|
docker compose up -d --build docs
|
|
|
|
.PHONY: dev
|
|
dev: ## Run the Astro dev server with HMR (--profile dev)
|
|
docker compose --profile dev up --build docs-dev
|
|
|
|
.PHONY: down
|
|
down: ## Stop and remove the docs containers
|
|
docker compose --profile dev down
|
|
docker compose down
|
|
|
|
.PHONY: logs
|
|
logs: ## Tail logs (works for whichever profile is up)
|
|
docker compose logs -f --tail=100
|
|
|
|
.PHONY: build
|
|
build: ## Build the static site WITHOUT bringing up Caddy (CI gate)
|
|
docker compose build docs
|
|
|
|
.PHONY: shell
|
|
shell: ## Open a shell in the running dev container (debugging)
|
|
docker compose exec docs-dev sh
|
|
|
|
# ---- Production deploy --------------------------------------------------
|
|
#
|
|
# `make deploy` pulls origin/main on the warehack.ing prod host and rebuilds
|
|
# the docs container. Agent-forwarding (`-A`) lets the remote `git pull` use
|
|
# the operator's local SSH key for Gitea — nothing persistent is provisioned
|
|
# on the deploy host.
|
|
#
|
|
# Override DEPLOY_HOST / DEPLOY_PATH for a different deployment without
|
|
# editing this file. The defaults are the warehack.ing cookie-cutter shape
|
|
# (see ~/.claude/references/warehacking.md).
|
|
|
|
DEPLOY_HOST ?= warehack-ing@warehack.ing
|
|
DEPLOY_PATH ?= ~/cuckoo-escapement
|
|
|
|
.PHONY: deploy
|
|
deploy: ## Pull main + rebuild the docs container on the prod host
|
|
@echo "==> deploying $(DEPLOY_HOST):$(DEPLOY_PATH)"
|
|
ssh -A $(DEPLOY_HOST) "cd $(DEPLOY_PATH) && git fetch origin main && git reset --hard origin/main && cd docs-site && make prod"
|
|
@echo "==> sanity check"
|
|
@curl -s -o /dev/null -w " HTTP %{http_code} %{url_effective}\n" "https://cuckoo.warehack.ing/explanation/preempt-rt-made-it-worse/"
|