name: Validate manifests on: push: pull_request: jobs: validate: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Install tools run: | curl -sL https://github.com/yannh/kubeconform/releases/latest/download/kubeconform-linux-amd64.tar.gz \ | tar xz -C /usr/local/bin curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash - name: Helm lint run: | found=0 for parent in helm custom-charts; do [ -d "$parent" ] || continue for chart in "$parent"/*; do [ -d "$chart" ] || continue found=1 echo "Linting $chart" helm lint "$chart" done done if [ "$found" -eq 0 ]; then echo "No Helm charts found" fi - name: kubeconform - raw YAML run: | bootstrap_enabled=false if [ -f bootstrap/config.yaml ] && grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then bootstrap_enabled=true fi mapfile -t manifests < <( find . -type f -name '*.yaml' \ ! -path './.gitea/*' \ ! -name 'kustomization.yaml' \ ! -name 'values.yaml' \ ! -path './bootstrap/config.yaml' \ | sort ) if [ "$bootstrap_enabled" != "true" ]; then filtered=() for manifest in "${manifests[@]}"; do [ "$manifest" = "./bootstrap/applicationset.yaml" ] && continue filtered+=("$manifest") done manifests=("${filtered[@]}") fi if [ "${#manifests[@]}" -eq 0 ]; then echo "No manifests found" exit 0 fi printf '%s\n' "${manifests[@]}" \ | xargs kubeconform \ -strict \ -kubernetes-version 1.35.0 \ -ignore-missing-schemas \ -schema-location default \ -schema-location 'https://git.olb42.com/olb042/kubeconform/raw/branch/main/crdSchemas/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json' \ -summary - name: Apply bootstrap Application env: KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }} run: | if [ "${GITHUB_EVENT_NAME:-}" != "push" ] || [ "${GITHUB_REF:-}" != "refs/heads/main" ]; then echo "Skipping bootstrap apply: only push events on main may apply" exit 0 fi if [ ! -f bootstrap/config.yaml ] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled" exit 0 fi if [ -z "${KUBECONFIG_B64:-}" ]; then echo "Warning: KUBECONFIG_B64 secret not set — skipping bootstrap apply" exit 0 fi curl -fsSL https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl \ -o /usr/local/bin/kubectl chmod +x /usr/local/bin/kubectl mkdir -p "${HOME}/.kube" printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config" kubectl apply -f bootstrap/application.yaml