PREFIX ?= /usr/local BINDIR := $(PREFIX)/bin LIBDIR := $(PREFIX)/lib/enodia-sentinel SYSTEMDDIR := /etc/systemd/system CONFDIR := /etc LOGDIR := /var/log/enodia-sentinel DOCDIR := $(PREFIX)/share/doc/enodia-sentinel TMPFILESDIR := /etc/tmpfiles.d GO_AGENT_BIN := $(CURDIR)/build/enodia-sentinel-go GO_CACHE ?= /tmp/enodia-go-cache .PHONY: install install-go uninstall uninstall-go enable enable-go disable disable-go status status-go logs logs-go check baseline drill test build-go generate-go test-go parity-go check-go-service release-artifacts clean # Installs the stdlib-only Python package as a plain directory + launcher # wrapper (no pip, no virtualenv, no site-packages). Zero runtime deps. install: install -d $(DESTDIR)$(LIBDIR) cp -r enodia_sentinel $(DESTDIR)$(LIBDIR)/ install -Dm755 packaging/enodia-sentinel.wrapper $(DESTDIR)$(BINDIR)/enodia-sentinel install -Dm755 src/sentinel-redteam $(DESTDIR)$(BINDIR)/sentinel-redteam install -Dm644 systemd/enodia-sentinel.service $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel.service install -Dm644 systemd/enodia-sentinel-web.service $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel-web.service install -Dm644 packaging/enodia-sentinel-fim.hook $(DESTDIR)/etc/pacman.d/hooks/enodia-sentinel-fim.hook install -Dm644 packaging/enodia-sentinel.tmpfiles $(DESTDIR)$(TMPFILESDIR)/enodia-sentinel.conf @if [ ! -e "$(DESTDIR)$(CONFDIR)/enodia-sentinel.toml" ]; then \ install -Dm644 config/enodia-sentinel.toml $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml; \ echo "Installed default config at $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml"; \ else \ install -Dm644 config/enodia-sentinel.toml $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml.new; \ echo "Existing config preserved; new template at $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml.new"; \ fi install -Dm644 README.md $(DESTDIR)$(DOCDIR)/README.md install -Dm644 docs/INDEX.md $(DESTDIR)$(DOCDIR)/INDEX.md install -Dm644 docs/COMMAND_REFERENCE.md $(DESTDIR)$(DOCDIR)/COMMAND_REFERENCE.md install -Dm644 docs/SCHEMAS.md $(DESTDIR)$(DOCDIR)/SCHEMAS.md install -Dm644 docs/PACKAGING.md $(DESTDIR)$(DOCDIR)/PACKAGING.md install -Dm644 docs/OPERATIONS.md $(DESTDIR)$(DOCDIR)/OPERATIONS.md install -Dm644 docs/RUNBOOKS.md $(DESTDIR)$(DOCDIR)/RUNBOOKS.md install -Dm644 docs/RULES.md $(DESTDIR)$(DOCDIR)/RULES.md install -Dm644 docs/SPECIFICATION.md $(DESTDIR)$(DOCDIR)/SPECIFICATION.md install -Dm644 docs/ROADMAP.md $(DESTDIR)$(DOCDIR)/ROADMAP.md install -Dm644 docs/THREAT_MODEL.md $(DESTDIR)$(DOCDIR)/THREAT_MODEL.md install -Dm644 docs/VERSION.json $(DESTDIR)$(DOCDIR)/VERSION.json install -Dm644 systemd/enodia-sentinel-ebpf.conf $(DESTDIR)$(DOCDIR)/examples/enodia-sentinel-ebpf.conf install -dm750 $(DESTDIR)$(LOGDIR) @echo "Installed. Run 'sudo make enable' to start the service." # Build and install the Go migration agent as an opt-in validation sidecar. # It deliberately has a distinct binary, unit, and state directory; this target # never replaces or enables the production Python service. install-go: build-go install -Dm755 $(GO_AGENT_BIN) $(DESTDIR)$(BINDIR)/enodia-sentinel-go install -Dm644 systemd/enodia-sentinel-go-sidecar.service $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel-go-sidecar.service @if [ ! -e "$(DESTDIR)$(CONFDIR)/enodia-sentinel.toml" ]; then \ install -Dm644 config/enodia-sentinel.toml $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml; \ echo "Installed default config at $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml"; \ else \ echo "Existing config preserved at $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml"; \ fi install -Dm644 go-agent/README.md $(DESTDIR)$(DOCDIR)/GO_AGENT.md @echo "Go sidecar installed but not enabled. Run 'sudo make enable-go' to start it." uninstall: rm -rf $(DESTDIR)$(LIBDIR) rm -f $(DESTDIR)$(BINDIR)/enodia-sentinel rm -f $(DESTDIR)$(BINDIR)/sentinel-redteam rm -f $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel.service rm -f $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel-web.service rm -f $(DESTDIR)/etc/pacman.d/hooks/enodia-sentinel-fim.hook rm -f $(DESTDIR)$(TMPFILESDIR)/enodia-sentinel.conf rm -f $(DESTDIR)$(CONFDIR)/enodia-sentinel.toml.new rm -rf $(DESTDIR)$(DOCDIR) @echo "Uninstalled. Config and logs preserved." uninstall-go: rm -f $(DESTDIR)$(BINDIR)/enodia-sentinel-go rm -f $(DESTDIR)$(SYSTEMDDIR)/enodia-sentinel-go-sidecar.service rm -f $(DESTDIR)$(DOCDIR)/GO_AGENT.md @echo "Go sidecar uninstalled. Shared config and sidecar state preserved." enable: systemctl daemon-reload systemctl enable --now enodia-sentinel.service enable-go: systemctl daemon-reload systemctl enable --now enodia-sentinel-go-sidecar.service disable: systemctl disable --now enodia-sentinel.service disable-go: systemctl disable --now enodia-sentinel-go-sidecar.service status: systemctl status enodia-sentinel.service --no-pager status-go: systemctl status enodia-sentinel-go-sidecar.service --no-pager logs: journalctl -u enodia-sentinel.service -f logs-go: journalctl -u enodia-sentinel-go-sidecar.service -f # Dev targets — run from the repo without installing. test: python3 -m unittest discover -s tests -v test-go: cd go-agent && GOCACHE=$(GO_CACHE) go test ./... build-go: install -d $(dir $(GO_AGENT_BIN)) cd go-agent && CGO_ENABLED=0 GOCACHE=$(GO_CACHE) go build -buildvcs=false -trimpath -ldflags='-s -w' -o $(GO_AGENT_BIN) ./cmd/enodia-sentinel-go generate-go: cd go-agent && go generate ./internal/ebpfsource parity-go: python3 scripts/check-go-parity.py check-go-service: systemd-analyze verify systemd/enodia-sentinel-go-sidecar.service python3 -m unittest tests.test_go_sidecar_packaging -v check: python3 -m enodia_sentinel.cli check baseline: python3 -m enodia_sentinel.cli baseline web: python3 -m enodia_sentinel.cli web drill: ./src/sentinel-redteam release-artifacts: packaging/release-artifacts.sh clean: find . -type d -name __pycache__ -prune -exec rm -rf {} + rm -f $(GO_AGENT_BIN)