justfile: harden and normalize move to _helper scripts #304

Merged
mysticalsoap merged 2 commits from refactor/justfile-scripts into trunk 2026-09-21 00:24:18 -04:00
Owner

Problem

harden and normalize were most of the justfile: two long bash bodies with guards, loops and the comments that explain the permission model, sitting in a file whose job is to be scannable. Nothing said where recipe logic should live, so the file grew that way.

Fix

Both move to _helper/harden.sh and _helper/normalize.sh, bodies and guards unchanged, and the recipes wrap them the way deploy wraps deploy.py. One comment in normalize now states the constraint (a general chmod sweep reaches acme.json, grafana.db and PGDATA) instead of the incident. CONTRIBUTING gains a Justfile section: a recipe is its comment line and an invocation; logic beyond a few lines is a script under _helper/.

Verification

  • just harden unprivileged: the root guard fires with the same message, exit 1.
  • just normalize and sudo just harden on the live tree: both print their summary line, no errors.
  • just --list unchanged. Justfile 172 lines, from ~250.
## Problem `harden` and `normalize` were most of the justfile: two long bash bodies with guards, loops and the comments that explain the permission model, sitting in a file whose job is to be scannable. Nothing said where recipe logic should live, so the file grew that way. ## Fix Both move to `_helper/harden.sh` and `_helper/normalize.sh`, bodies and guards unchanged, and the recipes wrap them the way `deploy` wraps `deploy.py`. One comment in normalize now states the constraint (a general chmod sweep reaches acme.json, grafana.db and PGDATA) instead of the incident. CONTRIBUTING gains a Justfile section: a recipe is its comment line and an invocation; logic beyond a few lines is a script under `_helper/`. ## Verification - `just harden` unprivileged: the root guard fires with the same message, exit 1. - `just normalize` and `sudo just harden` on the live tree: both print their summary line, no errors. - `just --list` unchanged. Justfile 172 lines, from ~250.
The two recipes were most of the justfile and the only ones with logic
worth reading on its own; the recipes now wrap them like deploy wraps
deploy.py.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
docs: justfile rule in CONTRIBUTING
All checks were successful
validate / validate (pull_request) Successful in 24s
9f735ad0e5
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
mysticalsoap deleted branch refactor/justfile-scripts 2026-09-21 00:24:18 -04:00
Sign in to join this conversation.
No description provided.