make deploy and make deploy-runner compile the working tree, not HEAD, so
whatever is on disk ships. migrations/ is embedded, which makes that worse
than shipping stray code: a migration file that exists only on disk still runs
against the production database on restart.
That is not hypothetical. 0027_body_format reached gitbay.org inside the
unrelated go-org include-fix deploy (!111), an hour before !113 merged it. No
data was harmed — every row in all five tables is still md — but production
spent that hour on a binary built from an unreviewed tree, and nothing said so.
preflight now refuses a dirty tree. The check is git status --porcelain, so
untracked files count: go:embed does not consult the index, and an untracked
migration is exactly what got through. ALLOW_DIRTY=1 ships an uncommitted
build on purpose.
Verified: clean tree passes, untracked-file-only fails, staged-but-uncommitted
fails, ALLOW_DIRTY=1 bypasses.
Ref #28.