PREFIX ?= /usr/local BINDIR := $(PREFIX)/bin LIBDIR := $(PREFIX)/lib/enodia-sentinel SYSTEMDDIR := /etc/systemd/system CONFDIR := /etc LOGDIR := /var/log/enodia-sentinel DOCDIR := $(PREFIX)/share/doc/enodia-sentinel TMPFILESDIR := /etc/tmpfiles.d .PHONY: install uninstall enable disable status logs check baseline drill test test-go parity-go release-artifacts clean # Installs the stdlib-only Python package as a plain directory + launcher # wrapper (no pip, no virtualenv, no site-packages). Zero runtime deps. install: install -d $(DESTDIR)$(LIBDIR) cp -r enodia_sentinel $(DESTDIR)$(LIBDIR)/ install -Dm755 packaging/enodia-sentinel.wrapper $(DESTDIR)$(BINDIR)/enodia-sentinel install -Dm755 src/sentinel-redteam $(DESTDIR)$(BINDIR)/sentinel-redteam install -Dm644 systemd/enodia-sentinel.service $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel.service install -Dm644 systemd/enodia-sentinel-web.service $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel-web.service install -Dm644 packaging/enodia-sentinel-fim.hook $(DESTDIR)/etc/pacman.d/hooks/enodia-sentinel-fim.hook install -Dm644 packaging/enodia-sentinel.tmpfiles $(DESTDIR)$(TMPFILESDIR)/enodia-sentinel.conf @if [ ! -e "$(DESTDIR)$(CONFDIR)/enodia-sentinel.toml" ]; then \ install -Dm644 config/enodia-sentinel.toml $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml; \ echo "Installed default config at $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml"; \ else \ install -Dm644 config/enodia-sentinel.toml $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml.new; \ echo "Existing config preserved; new template at $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml.new"; \ fi install -Dm644 README.md $(DESTDIR)$(DOCDIR)/README.md install -Dm644 docs/INDEX.md $(DESTDIR)$(DOCDIR)/INDEX.md install -Dm644 docs/COMMAND_REFERENCE.md $(DESTDIR)$(DOCDIR)/COMMAND_REFERENCE.md install -Dm644 docs/SCHEMAS.md $(DESTDIR)$(DOCDIR)/SCHEMAS.md install -Dm644 docs/PACKAGING.md $(DESTDIR)$(DOCDIR)/PACKAGING.md install -Dm644 docs/OPERATIONS.md $(DESTDIR)$(DOCDIR)/OPERATIONS.md install -Dm644 docs/RUNBOOKS.md $(DESTDIR)$(DOCDIR)/RUNBOOKS.md install -Dm644 docs/RULES.md $(DESTDIR)$(DOCDIR)/RULES.md install -Dm644 docs/SPECIFICATION.md $(DESTDIR)$(DOCDIR)/SPECIFICATION.md install -Dm644 docs/ROADMAP.md $(DESTDIR)$(DOCDIR)/ROADMAP.md install -Dm644 docs/THREAT_MODEL.md $(DESTDIR)$(DOCDIR)/THREAT_MODEL.md install -Dm644 docs/VERSION.json $(DESTDIR)$(DOCDIR)/VERSION.json install -Dm644 systemd/enodia-sentinel-ebpf.conf $(DESTDIR)$(DOCDIR)/examples/enodia-sentinel-ebpf.conf install -dm750 $(DESTDIR)$(LOGDIR) @echo "Installed. Run 'sudo make enable' to start the service." uninstall: rm -rf $(DESTDIR)$(LIBDIR) rm -f $(DESTDIR)$(BINDIR)/enodia-sentinel rm -f $(DESTDIR)$(BINDIR)/sentinel-redteam rm -f $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel.service rm -f $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel-web.service rm -f $(DESTDIR)/etc/pacman.d/hooks/enodia-sentinel-fim.hook rm -f $(DESTDIR)$(TMPFILESDIR)/enodia-sentinel.conf rm -f $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml.new rm -rf $(DESTDIR)$(DOCDIR) @echo "Uninstalled. Config and logs preserved." enable: systemctl daemon-reload systemctl enable --now enodia-sentinel.service disable: systemctl disable --now enodia-sentinel.service status: systemctl status enodia-sentinel.service --no-pager logs: journalctl -u enodia-sentinel.service -f # Dev targets — run from the repo without installing. test: python3 -m unittest discover -s tests -v test-go: cd go-agent && GOCACHE=/tmp/enodia-go-cache go test ./... parity-go: python3 scripts/check-go-parity.py check: python3 -m enodia_sentinel.cli check baseline: python3 -m enodia_sentinel.cli baseline web: python3 -m enodia_sentinel.cli web drill: ./src/sentinel-redteam release-artifacts: packaging/release-artifacts.sh clean: find . -type d -name __pycache__ -prune -exec rm -rf {} +