Initial authentik gitops app
Validate manifests / validate (push) Failing after 8s

This commit is contained in:
2026-04-20 01:03:25 +01:00
commit c85556e327
27 changed files with 1129 additions and 0 deletions
+38
View File
@@ -0,0 +1,38 @@
#!/usr/bin/env zsh
set -eu
repo_root=$(git rev-parse --show-toplevel 2>/dev/null || pwd)
sops_file="${repo_root}/.sops.yaml"
if [ ! -f "${sops_file}" ]; then
exit 0
fi
if command -v yq >/dev/null 2>&1; then
yq -r '.creation_rules[]?.path_regex | select(. != null)' "${sops_file}"
exit 0
fi
if command -v python3 >/dev/null 2>&1; then
python3 - "${sops_file}" <<'PY'
import sys
try:
import yaml
except Exception as exc:
raise SystemExit(f"python3 fallback requires PyYAML: {exc}")
with open(sys.argv[1], "r", encoding="utf-8") as handle:
data = yaml.safe_load(handle) or {}
for rule in data.get("creation_rules") or []:
regex = rule.get("path_regex")
if regex:
print(regex)
PY
exit 0
fi
echo "Unable to read .sops.yaml path_regex values: install yq or python3 with PyYAML" >&2
exit 1
+88
View File
@@ -0,0 +1,88 @@
#!/usr/bin/env zsh
matches_any_rule() {
local path="$1"
shift
local regex
for regex in "$@"; do
[[ -n "${regex}" ]] || continue
if [[ "${path}" =~ ${regex} ]]; then
return 0
fi
done
return 1
}
enc_to_plain() {
local enc="$1"
[[ "${enc}" == *.enc.yaml ]] || return 1
print -r -- "${enc%.enc.yaml}.yaml"
}
plain_to_enc() {
local plain="$1"
[[ "${plain}" == *.yaml ]] || return 1
if [[ "${plain}" == *.enc.yaml ]]; then
print -r -- "${plain}"
else
print -r -- "${plain%.yaml}.enc.yaml"
fi
}
hmac_sidecar_for_enc() {
local enc="$1"
print -r -- "${enc}.sync-hmac"
}
encrypt_plain_to_enc() {
local plain="$1"
local enc="$2"
sops --encrypt --input-type yaml --output-type yaml --output "${enc}" "${plain}"
}
decrypt_enc_to_plain() {
local enc="$1"
sops --decrypt "${enc}"
}
compute_hmac_for_file() {
local path="$1"
openssl dgst -sha256 -hmac "${SOPS_SYNC_HMAC_KEY}" "${path}" | awk '{print $NF}'
}
compute_hmac_for_stdin() {
openssl dgst -sha256 -hmac "${SOPS_SYNC_HMAC_KEY}" | awk '{print $NF}'
}
read_sidecar() {
local sidecar="$1"
[ -f "${sidecar}" ] || return 1
tr -d '\r\n' < "${sidecar}"
}
write_sidecar() {
local sidecar="$1"
local value="$2"
print -r -- "${value}" > "${sidecar}"
}
is_sops_encrypted_file() {
local path="$1"
[ -f "${path}" ] || return 1
grep -q 'sops:' "${path}" && grep -q 'ENC\[' "${path}"
}
has_unstaged_changes() {
local path="$1"
if git ls-files --error-unmatch -- "${path}" >/dev/null 2>&1; then
git diff --quiet -- "${path}" >/dev/null 2>&1
return $?
fi
if git diff --cached --name-only -- "${path}" | grep -Fxq "${path}"; then
git diff --quiet -- "${path}" >/dev/null 2>&1
return $?
fi
return 1
}