This commit is contained in:
@@ -14,22 +14,26 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
curl -sL https://github.com/yannh/kubeconform/releases/latest/download/kubeconform-linux-amd64.tar.gz \
|
curl -sL https://github.com/yannh/kubeconform/releases/latest/download/kubeconform-linux-amd64.tar.gz \
|
||||||
| tar xz -C /usr/local/bin
|
| tar xz -C /usr/local/bin
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
||||||
|
|
||||||
# Traefik IngressRoute is a CRD, so kubeconform needs an extra schema source.
|
- name: Helm lint
|
||||||
mkdir -p .ci-schemas/traefik.io
|
run: |
|
||||||
curl -fsSL https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/traefik.io/ingressroute_v1alpha1.json \
|
found=0
|
||||||
-o .ci-schemas/traefik.io/ingressroute_v1alpha1.json
|
|
||||||
cp .ci-schemas/traefik.io/ingressroute_v1alpha1.json .ci-schemas/traefik.io/IngressRoute_v1alpha1.json
|
|
||||||
cp .ci-schemas/traefik.io/ingressroute_v1alpha1.json .ci-schemas/traefik.io/IngressRoute.json
|
|
||||||
cp .ci-schemas/traefik.io/ingressroute_v1alpha1.json .ci-schemas/traefik.io/ingressroute.json
|
|
||||||
|
|
||||||
# ArgoCD Application is also a CRD.
|
for parent in helm custom-charts; do
|
||||||
mkdir -p .ci-schemas/argoproj.io
|
[ -d "$parent" ] || continue
|
||||||
curl -fsSL https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/argoproj.io/application_v1alpha1.json \
|
|
||||||
-o .ci-schemas/argoproj.io/application_v1alpha1.json
|
for chart in "$parent"/*; do
|
||||||
cp .ci-schemas/argoproj.io/application_v1alpha1.json .ci-schemas/argoproj.io/Application_v1alpha1.json
|
[ -d "$chart" ] || continue
|
||||||
cp .ci-schemas/argoproj.io/application_v1alpha1.json .ci-schemas/argoproj.io/Application.json
|
found=1
|
||||||
cp .ci-schemas/argoproj.io/application_v1alpha1.json .ci-schemas/argoproj.io/application.json
|
echo "Linting $chart"
|
||||||
|
helm lint "$chart"
|
||||||
|
done
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$found" -eq 0 ]; then
|
||||||
|
echo "No Helm charts found"
|
||||||
|
fi
|
||||||
|
|
||||||
- name: kubeconform - raw YAML
|
- name: kubeconform - raw YAML
|
||||||
run: |
|
run: |
|
||||||
@@ -41,21 +45,16 @@ jobs:
|
|||||||
mapfile -t manifests < <(
|
mapfile -t manifests < <(
|
||||||
find . -type f -name '*.yaml' \
|
find . -type f -name '*.yaml' \
|
||||||
! -path './.gitea/*' \
|
! -path './.gitea/*' \
|
||||||
! -name '.sops.yaml' \
|
|
||||||
! -name '*.secret.yaml' \
|
|
||||||
! -name 'kustomization.yaml' \
|
! -name 'kustomization.yaml' \
|
||||||
! \( -name 'secret*.yaml' \) \
|
! -name 'values.yaml' \
|
||||||
! \( -path '*/config/*' -prune \) \
|
|
||||||
! -path './bootstrap/config.yaml' \
|
! -path './bootstrap/config.yaml' \
|
||||||
! -path './bootstrap/badge.yaml' \
|
|
||||||
! \( -name '*patch*.yaml' \) \
|
|
||||||
| sort
|
| sort
|
||||||
)
|
)
|
||||||
|
|
||||||
if [ "$bootstrap_enabled" != "true" ]; then
|
if [ "$bootstrap_enabled" != "true" ]; then
|
||||||
filtered=()
|
filtered=()
|
||||||
for manifest in "${manifests[@]}"; do
|
for manifest in "${manifests[@]}"; do
|
||||||
[ "$manifest" = "./bootstrap/application.yaml" ] && continue
|
[ "$manifest" = "./bootstrap/applicationset.yaml" ] && continue
|
||||||
filtered+=("$manifest")
|
filtered+=("$manifest")
|
||||||
done
|
done
|
||||||
manifests=("${filtered[@]}")
|
manifests=("${filtered[@]}")
|
||||||
@@ -70,10 +69,8 @@ jobs:
|
|||||||
| xargs kubeconform \
|
| xargs kubeconform \
|
||||||
-strict \
|
-strict \
|
||||||
-kubernetes-version 1.35.0 \
|
-kubernetes-version 1.35.0 \
|
||||||
-schema-location default \
|
|
||||||
-ignore-missing-schemas \
|
-ignore-missing-schemas \
|
||||||
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
|
-schema-location default \
|
||||||
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
|
|
||||||
-schema-location 'https://git.olb42.com/olb042/kubeconform/raw/branch/main/crdSchemas/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json' \
|
-schema-location 'https://git.olb42.com/olb042/kubeconform/raw/branch/main/crdSchemas/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json' \
|
||||||
-summary
|
-summary
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user