#!/usr/bin/env bash set -euo pipefail mkdir -p .ci-schemas/argoproj.io .ci-schemas/traefik.io .ci-schemas/bitnami.com .ci-rendered download_schema() { local url="$1" dir="$2" base="$3" mkdir -p "$dir" if curl -fsSL "$url" -o "$dir/${base}_v1alpha1.json" 2>/dev/null; then cp "$dir/${base}_v1alpha1.json" "$dir/${base}.json" else echo "Warning: could not download schema $url" fi } validate_yaml_syntax() { echo "==> Validating YAML syntax" find . -type f \( -name '*.yaml' -o -name '*.yml' \) \ ! -path './.git/*' ! -path './.ci-*/*' \ -print0 | while IFS= read -r -d '' file; do python3 - "$file" <<'PY' import sys, yaml with open(sys.argv[1]) as f: list(yaml.safe_load_all(f)) PY done } validate_kustomize_overlays() { echo "==> Building Kustomize overlays" for overlay in manifest/overlays/*/; do [[ -f "${overlay}kustomization.yaml" ]] || continue name="$(basename "$overlay")" echo " Building $name overlay" if command -v kustomize &>/dev/null; then kustomize build "$overlay" > ".ci-rendered/kustomize-${name}.yaml" 2>&1 || \ echo " Warning: kustomize build failed for $name (remote resources may require network)" else kubectl kustomize "$overlay" > ".ci-rendered/kustomize-${name}.yaml" 2>&1 || \ echo " Warning: kubectl kustomize failed for $name" fi done } prepare_crd_schemas() { echo "==> Preparing CRD schemas" download_schema \ "https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/argoproj.io/applicationset_v1alpha1.json" \ ".ci-schemas/argoproj.io" "applicationset" download_schema \ "https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/traefik.io/ingressroute_v1alpha1.json" \ ".ci-schemas/traefik.io" "ingressroute" download_schema \ "https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/bitnami.com/sealedsecret_v1alpha1.json" \ ".ci-schemas/bitnami.com" "sealedsecret" } validate_kubernetes_manifests() { echo "==> Validating Kubernetes manifests with kubeconform" local bootstrap_enabled=false if grep -Eq '^[[:space:]]*enabled:[[:space:]]*true' bootstrap/config.yaml 2>/dev/null; then bootstrap_enabled=true fi find . -type f \( -name '*.yaml' -o -name '*.yml' \) \ ! -path './.git/*' ! -path './.gitea/*' ! -path './.ci-*/*' \ ! -name '*kustomization.yaml' ! -name 'config.yaml' \ ! -name '*.plain.yaml' ! -name '*.example.yaml' \ $( [[ "$bootstrap_enabled" != "true" ]] && echo "! -name 'applicationset.yaml'" ) \ | sort | xargs kubeconform \ -strict \ -kubernetes-version 1.35.0 \ -schema-location default \ -schema-location 'https://git.olb42.com/olb042/kubeconform/raw/branch/main/crdSchemas/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json' \ -ignore-missing-schemas \ -summary } if ! command -v python3 &>/dev/null; then echo "python3 required"; exit 1; fi if ! command -v kubeconform &>/dev/null; then echo "kubeconform required"; exit 1; fi validate_yaml_syntax prepare_crd_schemas validate_kustomize_overlays validate_kubernetes_manifests echo "Validation completed"