Compare commits
22
Commits
v1.12.1
...
3f7c00f1e7
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3f7c00f1e7 | ||
|
|
dcb3434b39 | ||
|
|
b865cdd697 | ||
|
|
4300baaa19 | ||
|
|
eef6d305dd | ||
|
|
a9c5e56a24 | ||
|
|
4e765e5c64 | ||
|
|
50dc06f634 | ||
|
|
992d3630e9 | ||
|
|
b8b5648d00 | ||
|
|
503c02b24c | ||
|
|
fce2468b2b | ||
|
|
30ff44c33b | ||
|
|
11fd063f95 | ||
|
|
70758f1d74 | ||
|
|
395bf58622 | ||
|
|
358bf3b06f | ||
|
|
298834cd9f | ||
|
|
a6dc98df0d | ||
|
|
04d506533e | ||
|
|
a8797ceedb | ||
|
|
c75c6f5172 |
@@ -24,6 +24,9 @@ jobs:
|
||||
git add VERSION
|
||||
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
|
||||
version=$(cat VERSION)
|
||||
major="${version%%.*}"
|
||||
git tag "v${version}"
|
||||
git tag -f "v${major}"
|
||||
git push
|
||||
git push --tags
|
||||
git push origin "refs/tags/v${version}"
|
||||
git push --force origin "refs/tags/v${major}"
|
||||
|
||||
@@ -2,6 +2,7 @@ ACTIONS := \
|
||||
docker \
|
||||
node \
|
||||
git/create_tag \
|
||||
git/promotion-gate \
|
||||
helm/diff \
|
||||
helm/template \
|
||||
helm/upgrade \
|
||||
|
||||
@@ -15,6 +15,7 @@ Reusable composite actions for Gitea CI/CD pipelines.
|
||||
| Action | Description |
|
||||
|---|---|
|
||||
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
|
||||
| [git/promotion-gate](git/promotion-gate/README.md) | Enforce which source branches may merge into which target branches |
|
||||
|
||||
### Helm
|
||||
|
||||
|
||||
@@ -0,0 +1,21 @@
|
||||
# Promotion Gate
|
||||
|
||||
<!-- action-docs-description source="action.yml" -->
|
||||
## Description
|
||||
|
||||
Enforce which source branches may merge into which target branches
|
||||
<!-- action-docs-description source="action.yml" -->
|
||||
|
||||
<!-- action-docs-inputs source="action.yml" -->
|
||||
## Inputs
|
||||
|
||||
| name | description | required | default |
|
||||
| --- | --- | --- | --- |
|
||||
| `rules` | <p>One rule per line: "target:allowed1,allowed2,…". Targets not listed are unrestricted. Allowed entries may use a trailing glob, e.g. <code>hotfix-*</code>. Leave empty (default) to skip entirely.</p> | `false` | `""` |
|
||||
<!-- action-docs-inputs source="action.yml" -->
|
||||
|
||||
<!-- action-docs-runs source="action.yml" -->
|
||||
## Runs
|
||||
|
||||
This action is a `composite` action.
|
||||
<!-- action-docs-runs source="action.yml" -->
|
||||
@@ -0,0 +1,75 @@
|
||||
name: Promotion Gate
|
||||
description: Enforce which source branches may merge into which target branches
|
||||
inputs:
|
||||
rules:
|
||||
description: |
|
||||
One rule per line: "target:allowed1,allowed2,...". Targets not
|
||||
listed are unrestricted. Allowed entries may use a trailing glob,
|
||||
e.g. `hotfix-*`. Leave empty (default) to skip entirely.
|
||||
default: ""
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
steps:
|
||||
- name: Check merge source is allowed for target branch
|
||||
shell: sh
|
||||
env:
|
||||
BASE: ${{ gitea.event.pull_request.base.ref }}
|
||||
HEAD: ${{ gitea.event.pull_request.head.ref }}
|
||||
RULES: ${{ inputs.rules }}
|
||||
run: |
|
||||
if [ -z "$RULES" ]; then
|
||||
echo "No promotion rules configured — skipping."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
rc=0
|
||||
found=0
|
||||
|
||||
oldIFS=$IFS
|
||||
IFS='
|
||||
'
|
||||
set -f
|
||||
set -- $RULES
|
||||
set +f
|
||||
IFS=$oldIFS
|
||||
|
||||
for line in "$@"; do
|
||||
if [ -z "$line" ]; then
|
||||
continue
|
||||
fi
|
||||
target=${line%%:*}
|
||||
allowed=${line#*:}
|
||||
if [ "$target" = "$line" ]; then
|
||||
continue
|
||||
fi
|
||||
if [ "$BASE" = "$target" ]; then
|
||||
found=1
|
||||
matched=0
|
||||
innerIFS=$IFS
|
||||
IFS=','
|
||||
for pat in $allowed; do
|
||||
IFS=$innerIFS
|
||||
case "$HEAD" in
|
||||
$pat)
|
||||
matched=1
|
||||
;;
|
||||
esac
|
||||
IFS=','
|
||||
done
|
||||
IFS=$innerIFS
|
||||
|
||||
if [ "$matched" -eq 1 ]; then
|
||||
echo "Allowed: '$HEAD' -> '$BASE' (matches: $allowed)"
|
||||
else
|
||||
echo "::error::$BASE only accepts merges from: $allowed — got '$HEAD'"
|
||||
rc=1
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [ "$found" -eq 0 ]; then
|
||||
echo "No promotion-source restriction configured for base '$BASE'"
|
||||
fi
|
||||
|
||||
exit $rc
|
||||
@@ -73,8 +73,3 @@ runs:
|
||||
fi
|
||||
helm dependency update "$CHART_PATH"
|
||||
helm diff upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS --context 5
|
||||
|
||||
- name: Remove kubeconfig
|
||||
if: always()
|
||||
shell: sh
|
||||
run: rm -f ~/.kube/config
|
||||
|
||||
@@ -68,8 +68,3 @@ runs:
|
||||
fi
|
||||
helm dependency update "$CHART_PATH"
|
||||
helm template "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
|
||||
|
||||
- name: Remove kubeconfig
|
||||
if: always()
|
||||
shell: sh
|
||||
run: rm -f ~/.kube/config
|
||||
|
||||
@@ -38,5 +38,9 @@ runs:
|
||||
git config user.email "gitea-actions@gitea.pixelparasol.com"
|
||||
git config user.name "Gitea Actions"
|
||||
git add releases/versions.yaml
|
||||
if git diff --cached --quiet; then
|
||||
echo "No version change for ${{ inputs.service }}, skipping commit"
|
||||
exit 0
|
||||
fi
|
||||
git commit -m "chore: update ${{ inputs.service }} to ${{ inputs.tag }}"
|
||||
git push
|
||||
|
||||
@@ -2,7 +2,7 @@ name: Configure Kubectl
|
||||
description: Configure kubectl for use with Kubernetes
|
||||
inputs:
|
||||
K8S_CONFIG:
|
||||
description: "The Kubernetes config (plain YAML)"
|
||||
description: "The base64-encoded Kubernetes config"
|
||||
required: true
|
||||
K8S_NAMESPACE:
|
||||
description: "The K8S namespace"
|
||||
@@ -28,7 +28,7 @@ runs:
|
||||
echo "Configuring kubectl for context=${{ inputs.K8S_CONTEXT }} namespace=${{ inputs.K8S_NAMESPACE }}"
|
||||
rm -f ~/.kube/config
|
||||
mkdir -p ~/.kube
|
||||
printf '%s' "$K8S_CONFIG" > ~/.kube/config
|
||||
printf '%s' "$K8S_CONFIG" | base64 -d > ~/.kube/config
|
||||
kubectl config set-context ${{ inputs.K8S_CONTEXT }} --cluster=${{ inputs.K8S_CONTEXT }} --namespace=${{ inputs.K8S_NAMESPACE }}
|
||||
kubectl config use-context ${{ inputs.K8S_CONTEXT }}
|
||||
echo "kubectl configured successfully"
|
||||
|
||||
@@ -18,6 +18,7 @@ Install dependencies, build, and upload a build artifact
|
||||
| `ARTIFACT_PATH` | <p>Path to upload as the artifact</p> | `false` | `dist` |
|
||||
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
||||
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
||||
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
||||
<!-- action-docs-inputs source="action.yml" -->
|
||||
|
||||
<!-- action-docs-runs source="action.yml" -->
|
||||
|
||||
@@ -22,6 +22,9 @@ inputs:
|
||||
WORKING_DIRECTORY:
|
||||
description: "Working directory for install, build, and artifact steps"
|
||||
default: "."
|
||||
UPLOAD_ARTIFACT:
|
||||
description: "Whether to upload the build artifact"
|
||||
default: "true"
|
||||
|
||||
runs:
|
||||
using: composite
|
||||
@@ -56,6 +59,7 @@ runs:
|
||||
cp node_modules/.prisma/client/libquery_engine-* build/prisma/
|
||||
|
||||
- name: Upload Build Artifact
|
||||
if: inputs.UPLOAD_ARTIFACT != 'false'
|
||||
uses: actions/upload-artifact@v3
|
||||
with:
|
||||
name: ${{ inputs.ARTIFACT_NAME }}
|
||||
|
||||
@@ -8,6 +8,7 @@ Composite action: install dependencies and run an npm test script.
|
||||
|---|---|---|
|
||||
| `INSTALL_CMD` | Install command | `npm ci` |
|
||||
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
||||
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
||||
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
||||
|
||||
## Usage
|
||||
@@ -18,6 +19,15 @@ Composite action: install dependencies and run an npm test script.
|
||||
TEST_SCRIPT: test:unit
|
||||
```
|
||||
|
||||
With extra args:
|
||||
|
||||
```yaml
|
||||
- uses: stat-tackler/stat-tackler-infra/test/npm@main
|
||||
with:
|
||||
TEST_SCRIPT: test:coverage
|
||||
TEST_ARGS: --silent --reporter=dot --test-timeout=30000
|
||||
```
|
||||
|
||||
### Common test scripts by project
|
||||
|
||||
| Project | Script | Runner |
|
||||
|
||||
+4
-1
@@ -8,6 +8,9 @@ inputs:
|
||||
TEST_SCRIPT:
|
||||
description: "npm script to run (must exist in package.json)"
|
||||
default: "test"
|
||||
TEST_ARGS:
|
||||
description: "Additional arguments to pass after -- to the test script"
|
||||
default: ""
|
||||
WORKING_DIRECTORY:
|
||||
description: "Directory to run commands in"
|
||||
default: "."
|
||||
@@ -37,4 +40,4 @@ runs:
|
||||
- name: Test
|
||||
shell: sh
|
||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||
run: npm run ${{ inputs.TEST_SCRIPT }}
|
||||
run: npm run ${{ inputs.TEST_SCRIPT }}${{ inputs.TEST_ARGS != '' && format(' -- {0}', inputs.TEST_ARGS) || '' }}
|
||||
|
||||
Reference in New Issue
Block a user