Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
02b8ae8a72 | ||
|
|
53165c2d53 | ||
|
|
9df18983c3 | ||
|
|
3f7c00f1e7 | ||
|
|
dcb3434b39 | ||
|
|
b865cdd697 | ||
|
|
4300baaa19 | ||
|
|
eef6d305dd | ||
|
|
a9c5e56a24 | ||
|
|
4e765e5c64 | ||
|
|
50dc06f634 | ||
|
|
992d3630e9 |
@@ -24,6 +24,9 @@ jobs:
|
|||||||
git add VERSION
|
git add VERSION
|
||||||
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
|
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
|
||||||
version=$(cat VERSION)
|
version=$(cat VERSION)
|
||||||
|
major="${version%%.*}"
|
||||||
git tag "v${version}"
|
git tag "v${version}"
|
||||||
|
git tag -f "v${major}"
|
||||||
git push
|
git push
|
||||||
git push --tags
|
git push origin "refs/tags/v${version}"
|
||||||
|
git push --force origin "refs/tags/v${major}"
|
||||||
|
|||||||
@@ -2,6 +2,7 @@ ACTIONS := \
|
|||||||
docker \
|
docker \
|
||||||
node \
|
node \
|
||||||
git/create_tag \
|
git/create_tag \
|
||||||
|
git/promotion-gate \
|
||||||
helm/diff \
|
helm/diff \
|
||||||
helm/template \
|
helm/template \
|
||||||
helm/upgrade \
|
helm/upgrade \
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ Reusable composite actions for Gitea CI/CD pipelines.
|
|||||||
| Action | Description |
|
| Action | Description |
|
||||||
|---|---|
|
|---|---|
|
||||||
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
|
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
|
||||||
|
| [git/promotion-gate](git/promotion-gate/README.md) | Enforce which source branches may merge into which target branches |
|
||||||
|
|
||||||
### Helm
|
### Helm
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
# Promotion Gate
|
||||||
|
|
||||||
|
<!-- action-docs-description source="action.yml" -->
|
||||||
|
## Description
|
||||||
|
|
||||||
|
Enforce which source branches may merge into which target branches
|
||||||
|
<!-- action-docs-description source="action.yml" -->
|
||||||
|
|
||||||
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
## Inputs
|
||||||
|
|
||||||
|
| name | description | required | default |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| `rules` | <p>One rule per line: "target:allowed1,allowed2,…". Targets not listed are unrestricted. Allowed entries may use a trailing glob, e.g. <code>hotfix-*</code>. Leave empty (default) to skip entirely.</p> | `false` | `""` |
|
||||||
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
## Runs
|
||||||
|
|
||||||
|
This action is a `composite` action.
|
||||||
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
@@ -0,0 +1,75 @@
|
|||||||
|
name: Promotion Gate
|
||||||
|
description: Enforce which source branches may merge into which target branches
|
||||||
|
inputs:
|
||||||
|
rules:
|
||||||
|
description: |
|
||||||
|
One rule per line: "target:allowed1,allowed2,...". Targets not
|
||||||
|
listed are unrestricted. Allowed entries may use a trailing glob,
|
||||||
|
e.g. `hotfix-*`. Leave empty (default) to skip entirely.
|
||||||
|
default: ""
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
- name: Check merge source is allowed for target branch
|
||||||
|
shell: sh
|
||||||
|
env:
|
||||||
|
BASE: ${{ gitea.event.pull_request.base.ref }}
|
||||||
|
HEAD: ${{ gitea.event.pull_request.head.ref }}
|
||||||
|
RULES: ${{ inputs.rules }}
|
||||||
|
run: |
|
||||||
|
if [ -z "$RULES" ]; then
|
||||||
|
echo "No promotion rules configured — skipping."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
rc=0
|
||||||
|
found=0
|
||||||
|
|
||||||
|
oldIFS=$IFS
|
||||||
|
IFS='
|
||||||
|
'
|
||||||
|
set -f
|
||||||
|
set -- $RULES
|
||||||
|
set +f
|
||||||
|
IFS=$oldIFS
|
||||||
|
|
||||||
|
for line in "$@"; do
|
||||||
|
if [ -z "$line" ]; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
target=${line%%:*}
|
||||||
|
allowed=${line#*:}
|
||||||
|
if [ "$target" = "$line" ]; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
if [ "$BASE" = "$target" ]; then
|
||||||
|
found=1
|
||||||
|
matched=0
|
||||||
|
innerIFS=$IFS
|
||||||
|
IFS=','
|
||||||
|
for pat in $allowed; do
|
||||||
|
IFS=$innerIFS
|
||||||
|
case "$HEAD" in
|
||||||
|
$pat)
|
||||||
|
matched=1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
IFS=','
|
||||||
|
done
|
||||||
|
IFS=$innerIFS
|
||||||
|
|
||||||
|
if [ "$matched" -eq 1 ]; then
|
||||||
|
echo "Allowed: '$HEAD' -> '$BASE' (matches: $allowed)"
|
||||||
|
else
|
||||||
|
echo "::error::$BASE only accepts merges from: $allowed — got '$HEAD'"
|
||||||
|
rc=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$found" -eq 0 ]; then
|
||||||
|
echo "No promotion-source restriction configured for base '$BASE'"
|
||||||
|
fi
|
||||||
|
|
||||||
|
exit $rc
|
||||||
@@ -19,6 +19,7 @@ Install dependencies, build, and upload a build artifact
|
|||||||
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
||||||
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
||||||
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
||||||
|
| `NPM_TOKEN` | <p>Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages.</p> | `false` | `""` |
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
|||||||
@@ -25,6 +25,9 @@ inputs:
|
|||||||
UPLOAD_ARTIFACT:
|
UPLOAD_ARTIFACT:
|
||||||
description: "Whether to upload the build artifact"
|
description: "Whether to upload the build artifact"
|
||||||
default: "true"
|
default: "true"
|
||||||
|
NPM_TOKEN:
|
||||||
|
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
|
||||||
|
default: ""
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
@@ -36,6 +39,16 @@ runs:
|
|||||||
with:
|
with:
|
||||||
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
|
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
|
||||||
|
|
||||||
|
- name: Configure private registry auth
|
||||||
|
if: inputs.NPM_TOKEN != ''
|
||||||
|
shell: sh
|
||||||
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
run: |
|
||||||
|
printf '%s\n%s\n' \
|
||||||
|
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
|
||||||
|
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
|
||||||
|
>> .npmrc
|
||||||
|
|
||||||
- name: Install
|
- name: Install
|
||||||
shell: sh
|
shell: sh
|
||||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ Composite action: install dependencies and run an npm test script.
|
|||||||
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
||||||
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
||||||
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
||||||
|
| `NPM_TOKEN` | Auth token for the private Gitea npm registry (`@stat-tackler` scope). Leave empty if the repo installs no private packages. | `` |
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
@@ -19,6 +20,15 @@ Composite action: install dependencies and run an npm test script.
|
|||||||
TEST_SCRIPT: test:unit
|
TEST_SCRIPT: test:unit
|
||||||
```
|
```
|
||||||
|
|
||||||
|
With a private `@stat-tackler` package in `package.json`:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: stat-tackler/stat-tackler-infra/test/npm@main
|
||||||
|
with:
|
||||||
|
TEST_SCRIPT: test:unit
|
||||||
|
NPM_TOKEN: ${{ secrets.REGISTRY_READ_WRITE_AGENT }}
|
||||||
|
```
|
||||||
|
|
||||||
With extra args:
|
With extra args:
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
|
|||||||
@@ -14,6 +14,9 @@ inputs:
|
|||||||
WORKING_DIRECTORY:
|
WORKING_DIRECTORY:
|
||||||
description: "Directory to run commands in"
|
description: "Directory to run commands in"
|
||||||
default: "."
|
default: "."
|
||||||
|
NPM_TOKEN:
|
||||||
|
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
|
||||||
|
default: ""
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
@@ -32,6 +35,16 @@ runs:
|
|||||||
key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }}
|
key: node-modules-${{ hashFiles(format('{0}/package-lock.json', inputs.WORKING_DIRECTORY)) }}
|
||||||
restore-keys: node-modules-
|
restore-keys: node-modules-
|
||||||
|
|
||||||
|
- name: Configure private registry auth
|
||||||
|
if: inputs.NPM_TOKEN != ''
|
||||||
|
shell: sh
|
||||||
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
run: |
|
||||||
|
printf '%s\n%s\n' \
|
||||||
|
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
|
||||||
|
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
|
||||||
|
>> .npmrc
|
||||||
|
|
||||||
- name: Install
|
- name: Install
|
||||||
shell: sh
|
shell: sh
|
||||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
|
|||||||
Reference in New Issue
Block a user