This commit is contained in:
@@ -48,6 +48,7 @@ jobs:
|
||||
! \( -path '*/config/*' -prune \) \
|
||||
! -path './bootstrap/config.yaml' \
|
||||
! -path './bootstrap/badge.yaml' \
|
||||
! \( -name '*patch*.yaml' \) \
|
||||
| sort
|
||||
)
|
||||
|
||||
@@ -70,25 +71,12 @@ jobs:
|
||||
-strict \
|
||||
-kubernetes-version 1.35.0 \
|
||||
-schema-location default \
|
||||
-ignore-missing-schemas
|
||||
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
|
||||
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
|
||||
-schema-location 'https://git.olb42.com/olb042/kubeconform/raw/branch/main/crdSchemas/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json'
|
||||
-summary
|
||||
|
||||
- name: SOPS - check no secret files committed unencrypted
|
||||
run: |
|
||||
fail=0
|
||||
|
||||
while IFS= read -r file; do
|
||||
if ! grep -q 'sops:' "$file"; then
|
||||
echo "ERROR: $file appears to be unencrypted"
|
||||
fail=1
|
||||
fi
|
||||
done < <(
|
||||
find . -type f \( -name '*.secret.yaml' -o -name '*.enc.yaml' \) | sort
|
||||
)
|
||||
|
||||
exit "$fail"
|
||||
|
||||
- name: Apply bootstrap Application
|
||||
env:
|
||||
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
|
||||
|
||||
Reference in New Issue
Block a user