name: Validate manifests on: push: pull_request: jobs: validate: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Install tools run: | curl -sL https://github.com/yannh/kubeconform/releases/latest/download/kubeconform-linux-amd64.tar.gz \ | tar xz -C /usr/local/bin curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash curl -fsSL https://github.com/mikefarah/yq/releases/latest/download/yq_linux_amd64 \ -o /usr/local/bin/yq chmod +x /usr/local/bin/yq mkdir -p .ci-schemas/argoproj.io curl -fsSL https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/argoproj.io/applicationset_v1alpha1.json \ -o .ci-schemas/argoproj.io/applicationset_v1alpha1.json cp .ci-schemas/argoproj.io/applicationset_v1alpha1.json .ci-schemas/argoproj.io/ApplicationSet_v1alpha1.json cp .ci-schemas/argoproj.io/applicationset_v1alpha1.json .ci-schemas/argoproj.io/ApplicationSet.json cp .ci-schemas/argoproj.io/applicationset_v1alpha1.json .ci-schemas/argoproj.io/applicationset.json - name: kubeconform - raw YAML run: | bootstrap_enabled=false if [ -f bootstrap/config.yaml ] && grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then bootstrap_enabled=true fi mapfile -t manifests < <( find . -type f -name '*.yaml' \ ! -path './.gitea/*' \ ! -path './manifest/overlays/*/helm-values/*' \ ! -path './bootstrap/config.yaml' \ | sort ) if [ "$bootstrap_enabled" != "true" ]; then filtered=() for manifest in "${manifests[@]}"; do [ "$manifest" = "./bootstrap/applicationset.yaml" ] && continue filtered+=("$manifest") done manifests=("${filtered[@]}") fi if [ "${#manifests[@]}" -eq 0 ]; then echo "No manifests found" exit 0 fi printf '%s\n' "${manifests[@]}" \ | xargs kubeconform \ -strict \ -kubernetes-version 1.35.0 \ -schema-location default \ -schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \ -schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \ -ignore-missing-schemas \ -summary - name: Helm template run: | chart_version=$(yq '.spec.generators[0].list.elements[0].chartVersion' bootstrap/applicationset.yaml) helm repo add sealed-secrets https://bitnami-labs.github.io/sealed-secrets helm repo update sealed-secrets helm template sealed-secrets-controller sealed-secrets/sealed-secrets \ --namespace kube-system \ --version "$chart_version" \ -f manifest/overlays/production/helm-values/values.yaml \ >/tmp/rendered.yaml kubeconform \ -strict \ -kubernetes-version 1.35.0 \ /tmp/rendered.yaml - name: Apply bootstrap ApplicationSet env: KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }} run: | if [ "${GITHUB_EVENT_NAME:-}" != "push" ] || [ "${GITHUB_REF:-}" != "refs/heads/main" ]; then echo "Skipping bootstrap apply: only push events on main may apply" exit 0 fi if [ ! -f bootstrap/config.yaml ] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled" exit 0 fi if [ -z "${KUBECONFIG_B64:-}" ]; then echo "KUBECONFIG_B64 secret is required to apply bootstrap/applicationset.yaml" exit 1 fi curl -fsSL https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl \ -o /usr/local/bin/kubectl chmod +x /usr/local/bin/kubectl mkdir -p "${HOME}/.kube" printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config" kubectl apply -f bootstrap/applicationset.yaml