Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
36 lines
1.1 KiB
Bash
Executable File
36 lines
1.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
event_name="${GITHUB_EVENT_NAME:-}"
|
|
git_ref="${GITHUB_REF:-}"
|
|
|
|
if [[ "$event_name" != "push" || "$git_ref" != "refs/heads/main" ]]; then
|
|
echo "Skipping bootstrap apply: only push events on main may apply"
|
|
exit 0
|
|
fi
|
|
|
|
if [[ ! -f bootstrap/config.yaml ]] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
|
|
echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled"
|
|
exit 0
|
|
fi
|
|
|
|
if [[ -z "${KUBECONFIG_B64:-}" ]]; then
|
|
echo "KUBECONFIG_B64 secret is required to apply bootstrap/applicationset.yaml"
|
|
exit 1
|
|
fi
|
|
|
|
curl -fsSL "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl" \
|
|
-o /usr/local/bin/kubectl
|
|
chmod +x /usr/local/bin/kubectl
|
|
|
|
mkdir -p "${HOME}/.kube"
|
|
printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config"
|
|
|
|
if ! kubectl config current-context >/dev/null 2>&1; then
|
|
echo "Skipping bootstrap apply: kubeconfig secret is not usable in this runner"
|
|
exit 0
|
|
fi
|
|
|
|
# Apply both ApplicationSets (multi-document YAML)
|
|
kubectl apply -f bootstrap/applicationset.yaml
|