Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
88 lines
3.1 KiB
Bash
Executable File
88 lines
3.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
mkdir -p .ci-schemas/argoproj.io .ci-schemas/traefik.io .ci-schemas/bitnami.com .ci-rendered
|
|
|
|
download_schema() {
|
|
local url="$1" dir="$2" base="$3"
|
|
mkdir -p "$dir"
|
|
if curl -fsSL "$url" -o "$dir/${base}_v1alpha1.json" 2>/dev/null; then
|
|
cp "$dir/${base}_v1alpha1.json" "$dir/${base}.json"
|
|
else
|
|
echo "Warning: could not download schema $url"
|
|
fi
|
|
}
|
|
|
|
validate_yaml_syntax() {
|
|
echo "==> Validating YAML syntax"
|
|
find . -type f \( -name '*.yaml' -o -name '*.yml' \) \
|
|
! -path './.git/*' ! -path './.ci-*/*' \
|
|
-print0 | while IFS= read -r -d '' file; do
|
|
python3 - "$file" <<'PY'
|
|
import sys, yaml
|
|
with open(sys.argv[1]) as f:
|
|
list(yaml.safe_load_all(f))
|
|
PY
|
|
done
|
|
}
|
|
|
|
validate_kustomize_overlays() {
|
|
echo "==> Building Kustomize overlays"
|
|
for overlay in manifest/overlays/*/; do
|
|
[[ -f "${overlay}kustomization.yaml" ]] || continue
|
|
name="$(basename "$overlay")"
|
|
echo " Building $name overlay"
|
|
if command -v kustomize &>/dev/null; then
|
|
kustomize build "$overlay" > ".ci-rendered/kustomize-${name}.yaml" 2>&1 || \
|
|
echo " Warning: kustomize build failed for $name (remote resources may require network)"
|
|
else
|
|
kubectl kustomize "$overlay" > ".ci-rendered/kustomize-${name}.yaml" 2>&1 || \
|
|
echo " Warning: kubectl kustomize failed for $name"
|
|
fi
|
|
done
|
|
}
|
|
|
|
prepare_crd_schemas() {
|
|
echo "==> Preparing CRD schemas"
|
|
download_schema \
|
|
"https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/argoproj.io/applicationset_v1alpha1.json" \
|
|
".ci-schemas/argoproj.io" "applicationset"
|
|
download_schema \
|
|
"https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/traefik.io/ingressroute_v1alpha1.json" \
|
|
".ci-schemas/traefik.io" "ingressroute"
|
|
download_schema \
|
|
"https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/bitnami.com/sealedsecret_v1alpha1.json" \
|
|
".ci-schemas/bitnami.com" "sealedsecret"
|
|
}
|
|
|
|
validate_kubernetes_manifests() {
|
|
echo "==> Validating Kubernetes manifests with kubeconform"
|
|
local bootstrap_enabled=false
|
|
if grep -Eq '^[[:space:]]*enabled:[[:space:]]*true' bootstrap/config.yaml 2>/dev/null; then
|
|
bootstrap_enabled=true
|
|
fi
|
|
|
|
find . -type f \( -name '*.yaml' -o -name '*.yml' \) \
|
|
! -path './.git/*' ! -path './.gitea/*' ! -path './.ci-*/*' \
|
|
! -name '*kustomization.yaml' ! -name 'config.yaml' \
|
|
! -name '*.plain.yaml' ! -name '*.example.yaml' \
|
|
$( [[ "$bootstrap_enabled" != "true" ]] && echo "! -name 'applicationset.yaml'" ) \
|
|
| sort | xargs kubeconform \
|
|
-strict \
|
|
-kubernetes-version 1.35.0 \
|
|
-schema-location default \
|
|
-schema-location 'https://git.olb42.com/olb042/kubeconform/raw/branch/main/crdSchemas/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json' \
|
|
-ignore-missing-schemas \
|
|
-summary
|
|
}
|
|
|
|
if ! command -v python3 &>/dev/null; then echo "python3 required"; exit 1; fi
|
|
if ! command -v kubeconform &>/dev/null; then echo "kubeconform required"; exit 1; fi
|
|
|
|
validate_yaml_syntax
|
|
prepare_crd_schemas
|
|
validate_kustomize_overlays
|
|
validate_kubernetes_manifests
|
|
|
|
echo "Validation completed"
|