Files
olb042 6f29be2987
Validate login GitOps repo / validate (push) Successful in 9s
feat: initial scaffold from helm-template
- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
2026-05-10 22:32:49 +01:00

36 lines
1.1 KiB
Bash
Executable File

#!/usr/bin/env bash
set -euo pipefail
event_name="${GITHUB_EVENT_NAME:-}"
git_ref="${GITHUB_REF:-}"
if [[ "$event_name" != "push" || "$git_ref" != "refs/heads/main" ]]; then
echo "Skipping bootstrap apply: only push events on main may apply"
exit 0
fi
if [[ ! -f bootstrap/config.yaml ]] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled"
exit 0
fi
if [[ -z "${KUBECONFIG_B64:-}" ]]; then
echo "KUBECONFIG_B64 secret is required to apply bootstrap/applicationset.yaml"
exit 1
fi
curl -fsSL "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" \
-o /usr/local/bin/kubectl
chmod +x /usr/local/bin/kubectl
mkdir -p "${HOME}/.kube"
printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config"
if ! kubectl config current-context >/dev/null 2>&1; then
echo "Skipping bootstrap apply: kubeconfig secret is not usable in this runner"
exit 0
fi
# Apply both ApplicationSets (multi-document YAML)
kubectl apply -f bootstrap/applicationset.yaml