Compare commits

...
31 Commits
Author SHA1 Message Date
gitea-actions 4300baaa19 chore: bump version [skip ci] 2026-09-09 22:53:59 +00:00
deac eef6d305dd STAT-115: Add claude/check-shared-block composite action (STAT-115)
publish.yaml / publish (push) Successful in 4s
Claude-Session: https://claude.ai/code/session_01FS9R1ZEc8Vu7hg2PmzqbpP
2026-09-09 18:46:40 -04:00
gitea-actions a9c5e56a24 chore: bump version [skip ci] 2026-08-21 19:03:47 +00:00
deac 4e765e5c64 add-promotion-gate-action: Add git/promotion-gate composite action
publish.yaml / publish (push) Successful in 4s
Enforces which source branches may merge into which target branches, configured via a rules input (one target:allowed,allowed per line, glob-capable). Empty rules (default) skips enforcement entirely, so repos can adopt it without immediately gating on rules they have not configured. Extracted for reuse across repos moving to a gitflow-style branch promotion model, starting with stat-tackler-api.
2026-08-21 14:57:03 -04:00
gitea-actions 50dc06f634 chore: bump version [skip ci] 2026-08-18 13:38:29 +00:00
deac 992d3630e9 ci: maintain a floating v1 major-version tag on release
publish.yaml / publish (push) Successful in 8s
Lets consumers pin actions to @v1 instead of an exact vX.Y.Z, so they
pick up fixes automatically without per-repo version bumps.
2026-08-18 09:38:15 -04:00
gitea-actions b8b5648d00 chore: bump version [skip ci] 2026-08-18 13:34:06 +00:00
deac 503c02b24c fix: skip commit/push in update_version when tag is unchanged
publish.yaml / publish (push) Successful in 8s
git commit was failing the step (and job) with "nothing to commit" when
the target tag already matched releases/versions.yaml, e.g. on a re-run
for the same commit SHA.
2026-08-18 09:33:33 -04:00
gitea-actions fce2468b2b chore: bump version [skip ci] 2026-06-05 21:25:12 +00:00
deac 30ff44c33b Merge branch 'main' of ssh://gitea.pixelparasol.com:4122/pixel-parasol-public/gitea-actions
/ publish (push) Successful in 7s
2026-06-05 17:24:54 -04:00
deac 11fd063f95 allow skip build artifact for node action 2026-06-05 17:24:49 -04:00
gitea-actions 70758f1d74 chore: bump version [skip ci] 2026-06-05 20:44:36 +00:00
deac 395bf58622 add additional args to test npm runs
/ publish (push) Successful in 7s
2026-06-05 16:44:27 -04:00
gitea-actions 358bf3b06f chore: bump version [skip ci] 2026-06-01 00:51:33 +00:00
deac 298834cd9f fix: remove kubeconfig cleanup from template and diff — kubeconfig must persist across pipeline steps
/ publish (push) Failing after 6s
2026-06-01 00:51:27 +00:00
deac a6dc98df0d fix: remove kubeconfig cleanup from template and diff — kubeconfig must persist across pipeline steps
/ publish (push) Successful in 7s
2026-06-01 00:51:26 +00:00
gitea-actions 04d506533e chore: bump version [skip ci] 2026-06-01 00:46:17 +00:00
deac a8797ceedb revert: restore base64 -d in kubectl/configure (fetch-secret outputs base64)
/ publish (push) Successful in 7s
2026-06-01 00:46:10 +00:00
gitea-actions c75c6f5172 chore: bump version [skip ci] 2026-06-01 00:38:34 +00:00
deac bac8715813 fix: accept plain YAML kubeconfig instead of base64-encoded
/ publish (push) Successful in 7s
2026-06-01 00:38:27 +00:00
gitea-actions 975efe3d37 chore: bump version [skip ci] 2026-05-31 23:39:13 +00:00
deac 87626040ca Merge branch 'main' of ssh://gitea.pixelparasol.com:4122/pixel-parasol-public/gitea-actions
/ publish (push) Successful in 7s
2026-05-31 19:39:02 -04:00
deac e7d71f95bf normalize the helm actions 2026-05-31 19:38:58 -04:00
gitea-actions 1d6a9e5763 chore: bump version [skip ci] 2026-05-31 23:15:26 +00:00
deac 2e9a99fe8f add tag prefix for docker images
/ publish (push) Successful in 7s
2026-05-31 19:15:15 -04:00
gitea-actions 107f3c70f5 chore: bump version [skip ci] 2026-05-29 17:34:33 +00:00
deac b394f79057 Merge branch 'main' of ssh://gitea.pixelparasol.com:4122/pixel-parasol-public/gitea-actions
/ publish (push) Successful in 7s
2026-05-29 13:34:22 -04:00
deac 8c99fa50a9 fix env vars 2026-05-29 13:34:18 -04:00
gitea-actions 6b7f573880 chore: bump version [skip ci] 2026-05-29 16:55:43 +00:00
deac b296b7af40 b64 that fucker so its one line
/ publish (push) Successful in 7s
2026-05-29 12:55:34 -04:00
gitea-actions 40dd6f9675 chore: bump version [skip ci] 2026-05-29 16:49:10 +00:00
22 changed files with 406 additions and 66 deletions
+4 -1
View File
@@ -24,6 +24,9 @@ jobs:
git add VERSION
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
version=$(cat VERSION)
major="${version%%.*}"
git tag "v${version}"
git tag -f "v${major}"
git push
git push --tags
git push origin "refs/tags/v${version}"
git push --force origin "refs/tags/v${major}"
+2
View File
@@ -1,7 +1,9 @@
ACTIONS := \
docker \
node \
claude/check-shared-block \
git/create_tag \
git/promotion-gate \
helm/diff \
helm/template \
helm/upgrade \
+7
View File
@@ -4,6 +4,12 @@ Reusable composite actions for Gitea CI/CD pipelines.
## Actions
### Claude
| Action | Description |
|---|---|
| [claude/check-shared-block](claude/check-shared-block/README.md) | Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra |
### Docker
| Action | Description |
@@ -15,6 +21,7 @@ Reusable composite actions for Gitea CI/CD pipelines.
| Action | Description |
|---|---|
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
| [git/promotion-gate](git/promotion-gate/README.md) | Enforce which source branches may merge into which target branches |
### Helm
+1 -1
View File
@@ -1 +1 @@
1.6.0
1.20.0
+44
View File
@@ -0,0 +1,44 @@
# Check Shared CLAUDE.md Block
<!-- action-docs-description source="action.yml" -->
## Description
Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
<!-- action-docs-description source="action.yml" -->
<!-- action-docs-inputs source="action.yml" -->
## Inputs
| name | description | required | default |
| --- | --- | --- | --- |
| `TARGET` | <p>Path to the CLAUDE.md file to check</p> | `false` | `CLAUDE.md` |
| `CANONICAL_URL` | <p>Raw URL of the canonical shared fragment</p> | `false` | `https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md` |
| `GITEA_TOKEN` | <p>Gitea token with read access to stat-tackler-infra, if it is private</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
## Runs
This action is a `composite` action.
<!-- action-docs-runs source="action.yml" -->
## Running locally
The check logic has no dependency on the composite action wrapper beyond
`curl`, `awk`, and `diff` on `PATH`. From a repo's root:
```bash
CANONICAL_URL=https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md \
TARGET=CLAUDE.md sh -c '
extract() { awk "/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}" "$1"; }
tmp=$(mktemp)
curl -sfSL "$CANONICAL_URL" -o "$tmp"
extract "$tmp" > "$tmp.canon"
extract "$TARGET" > "$tmp.mine"
diff -u "$tmp.canon" "$tmp.mine" && echo "matches canonical"
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
'
```
`GITEA_TOKEN` is only needed if `stat-tackler-infra` becomes private; it is
otherwise safe to omit.
+75
View File
@@ -0,0 +1,75 @@
name: Check Shared CLAUDE.md Block
description: Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
inputs:
TARGET:
description: "Path to the CLAUDE.md file to check"
default: "CLAUDE.md"
CANONICAL_URL:
description: "Raw URL of the canonical shared fragment"
default: "https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md"
GITEA_TOKEN:
description: "Gitea token with read access to stat-tackler-infra, if it is private"
default: ""
runs:
using: composite
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Check shared CLAUDE.md block
shell: sh
env:
TARGET: ${{ inputs.TARGET }}
CANONICAL_URL: ${{ inputs.CANONICAL_URL }}
GITEA_TOKEN: ${{ inputs.GITEA_TOKEN }}
run: |
set -e
if [ ! -f "$TARGET" ]; then
echo "::error::$TARGET not found"
exit 1
fi
extract() {
# Everything between the markers, markers included.
awk '/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}' "$1"
}
mine=$(extract "$TARGET")
if [ -z "$mine" ]; then
echo "::error::$TARGET has no SHARED:BEGIN/SHARED:END block."
echo "Copy it from $CANONICAL_URL"
exit 1
fi
tmp=$(mktemp)
if [ -n "$GITEA_TOKEN" ]; then
curl -sfSL -H "Authorization: token $GITEA_TOKEN" "$CANONICAL_URL" -o "$tmp"
else
curl -sfSL "$CANONICAL_URL" -o "$tmp"
fi
theirs=$(extract "$tmp")
if [ -z "$theirs" ]; then
echo "::error::Could not read the canonical block from $CANONICAL_URL"
exit 1
fi
if [ "$mine" = "$theirs" ]; then
echo "Shared CLAUDE.md block matches the canonical copy."
rm -f "$tmp"
exit 0
fi
echo "::error::The shared CLAUDE.md block has drifted from the canonical copy."
echo "Canonical: $CANONICAL_URL"
echo
echo "--- canonical"
echo "+++ $TARGET"
printf '%s\n' "$theirs" > "$tmp.canon"
printf '%s\n' "$mine" > "$tmp.mine"
diff -u "$tmp.canon" "$tmp.mine" || true
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
exit 1
+1
View File
@@ -20,6 +20,7 @@ Build a Docker image and push it to the Gitea container registry
| `ARTIFACT_NAME` | <p>Name of the build artifact to download</p> | `false` | `dist` |
| `ARTIFACT_PATH` | <p>Destination path for the downloaded artifact</p> | `false` | `dist` |
| `TAG_LATEST` | <p>Also tag and push the image as latest</p> | `false` | `false` |
| `TAG_PREFIX` | <p>Optional prefix to prepend to IMAGE_TAG (e.g. 'dev' produces 'dev-&lt;tag&gt;'). Does not affect the latest tag.</p> | `false` | `""` |
| `WORKING_DIRECTORY` | <p>Working directory for the Docker build</p> | `false` | `.` |
<!-- action-docs-inputs source="action.yml" -->
+8 -1
View File
@@ -28,6 +28,9 @@ inputs:
TAG_LATEST:
description: "Also tag and push the image as latest"
default: "false"
TAG_PREFIX:
description: "Optional prefix to prepend to IMAGE_TAG (e.g. 'dev' produces 'dev-<tag>'). Does not affect the latest tag."
default: ""
WORKING_DIRECTORY:
description: "Working directory for the Docker build"
default: "."
@@ -51,7 +54,11 @@ runs:
- name: Docker Build and Push
shell: sh
run: |
TAGS="-t ${{ inputs.IMAGE_PATH }}:${{ inputs.IMAGE_TAG }}"
TAG="${{ inputs.IMAGE_TAG }}"
if [ -n "${{ inputs.TAG_PREFIX }}" ]; then
TAG="${{ inputs.TAG_PREFIX }}-${TAG}"
fi
TAGS="-t ${{ inputs.IMAGE_PATH }}:${TAG}"
if [ "${{ inputs.TAG_LATEST }}" = "true" ]; then
TAGS="$TAGS -t ${{ inputs.IMAGE_PATH }}:latest"
fi
+21
View File
@@ -0,0 +1,21 @@
# Promotion Gate
<!-- action-docs-description source="action.yml" -->
## Description
Enforce which source branches may merge into which target branches
<!-- action-docs-description source="action.yml" -->
<!-- action-docs-inputs source="action.yml" -->
## Inputs
| name | description | required | default |
| --- | --- | --- | --- |
| `rules` | <p>One rule per line: "target:allowed1,allowed2,…". Targets not listed are unrestricted. Allowed entries may use a trailing glob, e.g. <code>hotfix-*</code>. Leave empty (default) to skip entirely.</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
## Runs
This action is a `composite` action.
<!-- action-docs-runs source="action.yml" -->
+75
View File
@@ -0,0 +1,75 @@
name: Promotion Gate
description: Enforce which source branches may merge into which target branches
inputs:
rules:
description: |
One rule per line: "target:allowed1,allowed2,...". Targets not
listed are unrestricted. Allowed entries may use a trailing glob,
e.g. `hotfix-*`. Leave empty (default) to skip entirely.
default: ""
runs:
using: composite
steps:
- name: Check merge source is allowed for target branch
shell: sh
env:
BASE: ${{ gitea.event.pull_request.base.ref }}
HEAD: ${{ gitea.event.pull_request.head.ref }}
RULES: ${{ inputs.rules }}
run: |
if [ -z "$RULES" ]; then
echo "No promotion rules configured — skipping."
exit 0
fi
rc=0
found=0
oldIFS=$IFS
IFS='
'
set -f
set -- $RULES
set +f
IFS=$oldIFS
for line in "$@"; do
if [ -z "$line" ]; then
continue
fi
target=${line%%:*}
allowed=${line#*:}
if [ "$target" = "$line" ]; then
continue
fi
if [ "$BASE" = "$target" ]; then
found=1
matched=0
innerIFS=$IFS
IFS=','
for pat in $allowed; do
IFS=$innerIFS
case "$HEAD" in
$pat)
matched=1
;;
esac
IFS=','
done
IFS=$innerIFS
if [ "$matched" -eq 1 ]; then
echo "Allowed: '$HEAD' -> '$BASE' (matches: $allowed)"
else
echo "::error::$BASE only accepts merges from: $allowed — got '$HEAD'"
rc=1
fi
fi
done
if [ "$found" -eq 0 ]; then
echo "No promotion-source restriction configured for base '$BASE'"
fi
exit $rc
+9 -7
View File
@@ -11,14 +11,16 @@ Diff a Helm chart for a deployment in a Kubernetes cluster
| name | description | required | default |
| --- | --- | --- | --- |
| `DEPLOYMENT_NAME` | <p>The Kubernetes Deployment to update</p> | `true` | `""` |
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace of the Deployment</p> | `true` | `""` |
| `IMAGE_PATH` | <p>The registry path to the image</p> | `true` | `""` |
| `IMAGE_TAG` | <p>The image tag to deploy</p> | `true` | `""` |
| `CONTAINER_NAME` | <p>The container component to update</p> | `true` | `""` |
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
| `DEPLOYMENT_NAME` | <p>The Helm release name</p> | `true` | `""` |
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace (defaults to DEPLOYMENT_NAME)</p> | `false` | `""` |
| `REGISTRY` | <p>OCI registry hostname for helm dependency login</p> | `true` | `""` |
| `REGISTRY_USERNAME` | <p>Username for OCI registry login</p> | `true` | `""` |
| `REGISTRY_TOKEN` | <p>Token for OCI registry login</p> | `true` | `""` |
| `CHART_PATH` | <p>Path to the Helm chart</p> | `false` | `./helm` |
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `true` | `""` |
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
| `IMAGE_PATH` | <p>The registry path to the image (optional)</p> | `false` | `""` |
| `IMAGE_TAG` | <p>The image tag to deploy (optional)</p> | `false` | `""` |
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
+50 -16
View File
@@ -2,40 +2,74 @@ name: Helm Diff Deployment
description: Diff a Helm chart for a deployment in a Kubernetes cluster
inputs:
DEPLOYMENT_NAME:
description: "The Kubernetes Deployment to update"
description: "The Helm release name"
required: true
DEPLOYMENT_NAMESPACE:
description: "The Kubernetes namespace of the Deployment"
description: "The Kubernetes namespace (defaults to DEPLOYMENT_NAME)"
default: ""
REGISTRY:
description: "OCI registry hostname for helm dependency login"
required: true
IMAGE_PATH:
description: "The registry path to the image"
REGISTRY_USERNAME:
description: "Username for OCI registry login"
required: true
IMAGE_TAG:
description: "The image tag to deploy"
REGISTRY_TOKEN:
description: "Token for OCI registry login"
required: true
CONTAINER_NAME:
description: "The container component to update"
required: true
VALUES_FILE:
description: "The values file to use"
default: "./helm/values.yaml"
CHART_PATH:
description: "Path to the Helm chart"
default: "./helm"
VALUES_FILE:
description: "The values file to use"
default: "./helm/values.yaml"
IMAGE_PATH:
description: "The registry path to the image (optional)"
default: ""
IMAGE_TAG:
description: "The image tag to deploy (optional)"
default: ""
TAG_KEY:
description: "Helm --set key for the image tag (e.g. deploy.api.tag)"
required: true
default: ""
runs:
using: composite
steps:
- name: Helm OCI Login
shell: sh
env:
REGISTRY: ${{ inputs.REGISTRY }}
REGISTRY_USERNAME: ${{ inputs.REGISTRY_USERNAME }}
REGISTRY_TOKEN: ${{ inputs.REGISTRY_TOKEN }}
run: |
echo "$REGISTRY_TOKEN" | helm registry login "$REGISTRY" \
--username "$REGISTRY_USERNAME" \
--password-stdin
- name: Install Helm Diff
shell: sh
run: |
helm plugin list | grep -q diff || helm plugin install https://github.com/databus23/helm-diff
- name: Helm Diff
shell: sh
env:
DEPLOYMENT_NAME: ${{ inputs.DEPLOYMENT_NAME }}
DEPLOYMENT_NAMESPACE: ${{ inputs.DEPLOYMENT_NAMESPACE }}
CHART_PATH: ${{ inputs.CHART_PATH }}
VALUES_FILE: ${{ inputs.VALUES_FILE }}
IMAGE_PATH: ${{ inputs.IMAGE_PATH }}
IMAGE_TAG: ${{ inputs.IMAGE_TAG }}
TAG_KEY: ${{ inputs.TAG_KEY }}
run: |
CMD="helm diff upgrade ${{ inputs.DEPLOYMENT_NAME }} ${{ inputs.CHART_PATH }} -n ${{ inputs.DEPLOYMENT_NAMESPACE }} --values ${{ inputs.VALUES_FILE }} --set ${TAG_KEY}=${{ inputs.IMAGE_TAG }} --set image.repository=${{ inputs.IMAGE_PATH }} --context 5"
echo "Running: $CMD"
eval "$CMD"
NAMESPACE="$DEPLOYMENT_NAMESPACE"
if [ -z "$NAMESPACE" ]; then NAMESPACE="$DEPLOYMENT_NAME"; fi
SET_FLAGS=""
if [ -n "$TAG_KEY" ] && [ -n "$IMAGE_TAG" ]; then
SET_FLAGS="$SET_FLAGS --set $TAG_KEY=$IMAGE_TAG"
fi
if [ -n "$IMAGE_PATH" ]; then
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
fi
helm dependency update "$CHART_PATH"
helm diff upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS --context 5
+9 -7
View File
@@ -11,14 +11,16 @@ Template a Helm chart for a deployment in a Kubernetes cluster
| name | description | required | default |
| --- | --- | --- | --- |
| `DEPLOYMENT_NAME` | <p>The Kubernetes Deployment to update</p> | `true` | `""` |
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace of the Deployment</p> | `true` | `""` |
| `IMAGE_PATH` | <p>The registry path to the image</p> | `true` | `""` |
| `IMAGE_TAG` | <p>The image tag to deploy</p> | `true` | `""` |
| `CONTAINER_NAME` | <p>The container component to update</p> | `true` | `""` |
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
| `DEPLOYMENT_NAME` | <p>The Helm release name</p> | `true` | `""` |
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace (defaults to DEPLOYMENT_NAME)</p> | `false` | `""` |
| `REGISTRY` | <p>OCI registry hostname for helm dependency login</p> | `true` | `""` |
| `REGISTRY_USERNAME` | <p>Username for OCI registry login</p> | `true` | `""` |
| `REGISTRY_TOKEN` | <p>Token for OCI registry login</p> | `true` | `""` |
| `CHART_PATH` | <p>Path to the Helm chart</p> | `false` | `./helm` |
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `true` | `""` |
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
| `IMAGE_PATH` | <p>The registry path to the image (optional)</p> | `false` | `""` |
| `IMAGE_TAG` | <p>The image tag to deploy (optional)</p> | `false` | `""` |
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
+49 -16
View File
@@ -2,36 +2,69 @@ name: Helm Template Deployment
description: Template a Helm chart for a deployment in a Kubernetes cluster
inputs:
DEPLOYMENT_NAME:
description: "The Kubernetes Deployment to update"
description: "The Helm release name"
required: true
DEPLOYMENT_NAMESPACE:
description: "The Kubernetes namespace of the Deployment"
description: "The Kubernetes namespace (defaults to DEPLOYMENT_NAME)"
default: ""
REGISTRY:
description: "OCI registry hostname for helm dependency login"
required: true
IMAGE_PATH:
description: "The registry path to the image"
REGISTRY_USERNAME:
description: "Username for OCI registry login"
required: true
IMAGE_TAG:
description: "The image tag to deploy"
REGISTRY_TOKEN:
description: "Token for OCI registry login"
required: true
CONTAINER_NAME:
description: "The container component to update"
required: true
VALUES_FILE:
description: "The values file to use"
default: "./helm/values.yaml"
CHART_PATH:
description: "Path to the Helm chart"
default: "./helm"
VALUES_FILE:
description: "The values file to use"
default: "./helm/values.yaml"
IMAGE_PATH:
description: "The registry path to the image (optional)"
default: ""
IMAGE_TAG:
description: "The image tag to deploy (optional)"
default: ""
TAG_KEY:
description: "Helm --set key for the image tag (e.g. deploy.api.tag)"
required: true
default: ""
runs:
using: composite
steps:
- name: Helm OCI Login
shell: sh
env:
REGISTRY: ${{ inputs.REGISTRY }}
REGISTRY_USERNAME: ${{ inputs.REGISTRY_USERNAME }}
REGISTRY_TOKEN: ${{ inputs.REGISTRY_TOKEN }}
run: |
echo "$REGISTRY_TOKEN" | helm registry login "$REGISTRY" \
--username "$REGISTRY_USERNAME" \
--password-stdin
- name: Helm Template
shell: sh
env:
DEPLOYMENT_NAME: ${{ inputs.DEPLOYMENT_NAME }}
DEPLOYMENT_NAMESPACE: ${{ inputs.DEPLOYMENT_NAMESPACE }}
CHART_PATH: ${{ inputs.CHART_PATH }}
VALUES_FILE: ${{ inputs.VALUES_FILE }}
IMAGE_PATH: ${{ inputs.IMAGE_PATH }}
IMAGE_TAG: ${{ inputs.IMAGE_TAG }}
TAG_KEY: ${{ inputs.TAG_KEY }}
run: |
CMD="helm template ${{ inputs.DEPLOYMENT_NAME }} ${{ inputs.CHART_PATH }} -n ${{ inputs.DEPLOYMENT_NAMESPACE }} --values ${{ inputs.VALUES_FILE }} --set ${TAG_KEY}=${{ inputs.IMAGE_TAG }} --set image.repository=${{ inputs.IMAGE_PATH }}"
echo "Running: $CMD"
eval "$CMD"
NAMESPACE="$DEPLOYMENT_NAMESPACE"
if [ -z "$NAMESPACE" ]; then NAMESPACE="$DEPLOYMENT_NAME"; fi
SET_FLAGS=""
if [ -n "$TAG_KEY" ] && [ -n "$IMAGE_TAG" ]; then
SET_FLAGS="$SET_FLAGS --set $TAG_KEY=$IMAGE_TAG"
fi
if [ -n "$IMAGE_PATH" ]; then
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
fi
helm dependency update "$CHART_PATH"
helm template "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
+22 -11
View File
@@ -37,26 +37,37 @@ runs:
steps:
- name: Helm OCI Login
shell: sh
env:
REGISTRY: ${{ inputs.REGISTRY }}
REGISTRY_USERNAME: ${{ inputs.REGISTRY_USERNAME }}
REGISTRY_TOKEN: ${{ inputs.REGISTRY_TOKEN }}
run: |
echo "${{ inputs.REGISTRY_TOKEN }}" | helm registry login ${{ inputs.REGISTRY }} \
--username ${{ inputs.REGISTRY_USERNAME }} \
echo "$REGISTRY_TOKEN" | helm registry login "$REGISTRY" \
--username "$REGISTRY_USERNAME" \
--password-stdin
- name: Helm Upgrade
shell: sh
env:
DEPLOYMENT_NAME: ${{ inputs.DEPLOYMENT_NAME }}
DEPLOYMENT_NAMESPACE: ${{ inputs.DEPLOYMENT_NAMESPACE }}
CHART_PATH: ${{ inputs.CHART_PATH }}
VALUES_FILE: ${{ inputs.VALUES_FILE }}
IMAGE_PATH: ${{ inputs.IMAGE_PATH }}
IMAGE_TAG: ${{ inputs.IMAGE_TAG }}
TAG_KEY: ${{ inputs.TAG_KEY }}
run: |
NAMESPACE="${{ inputs.DEPLOYMENT_NAMESPACE }}"
if [ -z "$NAMESPACE" ]; then NAMESPACE="${{ inputs.DEPLOYMENT_NAME }}"; fi
NAMESPACE="$DEPLOYMENT_NAMESPACE"
if [ -z "$NAMESPACE" ]; then NAMESPACE="$DEPLOYMENT_NAME"; fi
SET_FLAGS=""
if [ -n "${{ inputs.TAG_KEY }}" ] && [ -n "${{ inputs.IMAGE_TAG }}" ]; then
SET_FLAGS="$SET_FLAGS --set ${{ inputs.TAG_KEY }}=${{ inputs.IMAGE_TAG }}"
if [ -n "$TAG_KEY" ] && [ -n "$IMAGE_TAG" ]; then
SET_FLAGS="$SET_FLAGS --set $TAG_KEY=$IMAGE_TAG"
fi
if [ -n "${{ inputs.IMAGE_PATH }}" ]; then
SET_FLAGS="$SET_FLAGS --set image.repository=${{ inputs.IMAGE_PATH }}"
if [ -n "$IMAGE_PATH" ]; then
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
fi
helm dependency update ${{ inputs.CHART_PATH }}
echo "Running: helm upgrade ${{ inputs.DEPLOYMENT_NAME }} ${{ inputs.CHART_PATH }} -n ${NAMESPACE} --values ${{ inputs.VALUES_FILE }}${SET_FLAGS}"
helm upgrade ${{ inputs.DEPLOYMENT_NAME }} ${{ inputs.CHART_PATH }} -n ${NAMESPACE} --values ${{ inputs.VALUES_FILE }} $SET_FLAGS
helm dependency update "$CHART_PATH"
helm upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
- name: Remove kubeconfig
if: always()
+4 -3
View File
@@ -24,7 +24,7 @@ inputs:
default: "/"
outputs:
value:
description: "The fetched secret value"
description: "The fetched secret value (base64-encoded)"
value: ${{ steps.fetch.outputs.value }}
runs:
@@ -61,10 +61,11 @@ runs:
exit 1
fi
echo "::add-mask::$VALUE"
B64=$(printf '%s' "$VALUE" | base64 | tr -d '\n')
echo "::add-mask::$B64"
DELIMITER="INFISICAL_EOF_$$"
echo "value<<${DELIMITER}" >> "$GITHUB_OUTPUT"
echo "$VALUE" >> "$GITHUB_OUTPUT"
printf '%s\n' "$B64" >> "$GITHUB_OUTPUT"
echo "${DELIMITER}" >> "$GITHUB_OUTPUT"
echo "Successfully fetched secret '${{ inputs.SECRET_NAME }}'"
+4
View File
@@ -38,5 +38,9 @@ runs:
git config user.email "gitea-actions@gitea.pixelparasol.com"
git config user.name "Gitea Actions"
git add releases/versions.yaml
if git diff --cached --quiet; then
echo "No version change for ${{ inputs.service }}, skipping commit"
exit 0
fi
git commit -m "chore: update ${{ inputs.service }} to ${{ inputs.tag }}"
git push
+2 -2
View File
@@ -2,7 +2,7 @@ name: Configure Kubectl
description: Configure kubectl for use with Kubernetes
inputs:
K8S_CONFIG:
description: "The RAW Kubernetes config"
description: "The base64-encoded Kubernetes config"
required: true
K8S_NAMESPACE:
description: "The K8S namespace"
@@ -28,7 +28,7 @@ runs:
echo "Configuring kubectl for context=${{ inputs.K8S_CONTEXT }} namespace=${{ inputs.K8S_NAMESPACE }}"
rm -f ~/.kube/config
mkdir -p ~/.kube
printf '%s' "$K8S_CONFIG" > ~/.kube/config
printf '%s' "$K8S_CONFIG" | base64 -d > ~/.kube/config
kubectl config set-context ${{ inputs.K8S_CONTEXT }} --cluster=${{ inputs.K8S_CONTEXT }} --namespace=${{ inputs.K8S_NAMESPACE }}
kubectl config use-context ${{ inputs.K8S_CONTEXT }}
echo "kubectl configured successfully"
+1
View File
@@ -18,6 +18,7 @@ Install dependencies, build, and upload a build artifact
| `ARTIFACT_PATH` | <p>Path to upload as the artifact</p> | `false` | `dist` |
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
+4
View File
@@ -22,6 +22,9 @@ inputs:
WORKING_DIRECTORY:
description: "Working directory for install, build, and artifact steps"
default: "."
UPLOAD_ARTIFACT:
description: "Whether to upload the build artifact"
default: "true"
runs:
using: composite
@@ -56,6 +59,7 @@ runs:
cp node_modules/.prisma/client/libquery_engine-* build/prisma/
- name: Upload Build Artifact
if: inputs.UPLOAD_ARTIFACT != 'false'
uses: actions/upload-artifact@v3
with:
name: ${{ inputs.ARTIFACT_NAME }}
+10
View File
@@ -8,6 +8,7 @@ Composite action: install dependencies and run an npm test script.
|---|---|---|
| `INSTALL_CMD` | Install command | `npm ci` |
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
## Usage
@@ -18,6 +19,15 @@ Composite action: install dependencies and run an npm test script.
TEST_SCRIPT: test:unit
```
With extra args:
```yaml
- uses: stat-tackler/stat-tackler-infra/test/npm@main
with:
TEST_SCRIPT: test:coverage
TEST_ARGS: --silent --reporter=dot --test-timeout=30000
```
### Common test scripts by project
| Project | Script | Runner |
+4 -1
View File
@@ -8,6 +8,9 @@ inputs:
TEST_SCRIPT:
description: "npm script to run (must exist in package.json)"
default: "test"
TEST_ARGS:
description: "Additional arguments to pass after -- to the test script"
default: ""
WORKING_DIRECTORY:
description: "Directory to run commands in"
default: "."
@@ -37,4 +40,4 @@ runs:
- name: Test
shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }}
run: npm run ${{ inputs.TEST_SCRIPT }}
run: npm run ${{ inputs.TEST_SCRIPT }}${{ inputs.TEST_ARGS != '' && format(' -- {0}', inputs.TEST_ARGS) || '' }}