109 lines
4.3 KiB
YAML
109 lines
4.3 KiB
YAML
name: Validate manifests
|
|
|
|
on:
|
|
push:
|
|
pull_request:
|
|
|
|
jobs:
|
|
validate:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install tools
|
|
run: |
|
|
curl -sL https://github.com/yannh/kubeconform/releases/latest/download/kubeconform-linux-amd64.tar.gz \
|
|
| tar xz -C /usr/local/bin
|
|
curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
|
curl -fsSL https://github.com/mikefarah/yq/releases/latest/download/yq_linux_amd64 \
|
|
-o /usr/local/bin/yq
|
|
chmod +x /usr/local/bin/yq
|
|
|
|
mkdir -p .ci-schemas/argoproj.io
|
|
curl -fsSL https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/argoproj.io/applicationset_v1alpha1.json \
|
|
-o .ci-schemas/argoproj.io/applicationset_v1alpha1.json
|
|
cp .ci-schemas/argoproj.io/applicationset_v1alpha1.json .ci-schemas/argoproj.io/ApplicationSet_v1alpha1.json
|
|
cp .ci-schemas/argoproj.io/applicationset_v1alpha1.json .ci-schemas/argoproj.io/ApplicationSet.json
|
|
cp .ci-schemas/argoproj.io/applicationset_v1alpha1.json .ci-schemas/argoproj.io/applicationset.json
|
|
|
|
- name: kubeconform - raw YAML
|
|
run: |
|
|
bootstrap_enabled=false
|
|
if [ -f bootstrap/config.yaml ] && grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
|
|
bootstrap_enabled=true
|
|
fi
|
|
|
|
mapfile -t manifests < <(
|
|
find . -type f -name '*.yaml' \
|
|
! -path './.gitea/*' \
|
|
! -path './manifest/overlays/*/helm-values/*' \
|
|
! -path './bootstrap/config.yaml' \
|
|
| sort
|
|
)
|
|
|
|
if [ "$bootstrap_enabled" != "true" ]; then
|
|
filtered=()
|
|
for manifest in "${manifests[@]}"; do
|
|
[ "$manifest" = "./bootstrap/applicationset.yaml" ] && continue
|
|
filtered+=("$manifest")
|
|
done
|
|
manifests=("${filtered[@]}")
|
|
fi
|
|
|
|
if [ "${#manifests[@]}" -eq 0 ]; then
|
|
echo "No manifests found"
|
|
exit 0
|
|
fi
|
|
|
|
printf '%s\n' "${manifests[@]}" \
|
|
| xargs kubeconform \
|
|
-strict \
|
|
-kubernetes-version 1.35.0 \
|
|
-schema-location default \
|
|
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}{{.KindSuffix}}.json' \
|
|
-schema-location '.ci-schemas/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
|
|
-summary
|
|
|
|
- name: Helm template
|
|
run: |
|
|
chart_version=$(yq '.spec.generators[0].list.elements[0].chartVersion' bootstrap/applicationset.yaml)
|
|
helm repo add sealed-secrets https://bitnami-labs.github.io/sealed-secrets
|
|
helm repo update sealed-secrets
|
|
helm template sealed-secrets-controller sealed-secrets/sealed-secrets \
|
|
--namespace kube-system \
|
|
--version "$chart_version" \
|
|
-f manifest/overlays/production/helm-values/values.yaml \
|
|
>/tmp/rendered.yaml
|
|
kubeconform \
|
|
-strict \
|
|
-kubernetes-version 1.35.0 \
|
|
/tmp/rendered.yaml
|
|
|
|
- name: Apply bootstrap ApplicationSet
|
|
env:
|
|
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
|
|
run: |
|
|
if [ "${GITHUB_EVENT_NAME:-}" != "push" ] || [ "${GITHUB_REF:-}" != "refs/heads/main" ]; then
|
|
echo "Skipping bootstrap apply: only push events on main may apply"
|
|
exit 0
|
|
fi
|
|
|
|
if [ ! -f bootstrap/config.yaml ] || ! grep -Eq '^[[:space:]]*enabled:[[:space:]]*true[[:space:]]*$' bootstrap/config.yaml; then
|
|
echo "Skipping bootstrap apply: bootstrap/config.yaml is not enabled"
|
|
exit 0
|
|
fi
|
|
|
|
if [ -z "${KUBECONFIG_B64:-}" ]; then
|
|
echo "KUBECONFIG_B64 secret is required to apply bootstrap/applicationset.yaml"
|
|
exit 1
|
|
fi
|
|
|
|
curl -fsSL https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl \
|
|
-o /usr/local/bin/kubectl
|
|
chmod +x /usr/local/bin/kubectl
|
|
|
|
mkdir -p "${HOME}/.kube"
|
|
printf '%s' "$KUBECONFIG_B64" | base64 -d > "${HOME}/.kube/config"
|
|
|
|
kubectl apply -f bootstrap/applicationset.yaml
|