Compare commits
25
Commits
v1.9.0
...
4300baaa19
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4300baaa19 | ||
|
|
eef6d305dd | ||
|
|
a9c5e56a24 | ||
|
|
4e765e5c64 | ||
|
|
50dc06f634 | ||
|
|
992d3630e9 | ||
|
|
b8b5648d00 | ||
|
|
503c02b24c | ||
|
|
fce2468b2b | ||
|
|
30ff44c33b | ||
|
|
11fd063f95 | ||
|
|
70758f1d74 | ||
|
|
395bf58622 | ||
|
|
358bf3b06f | ||
|
|
298834cd9f | ||
|
|
a6dc98df0d | ||
|
|
04d506533e | ||
|
|
a8797ceedb | ||
|
|
c75c6f5172 | ||
|
|
bac8715813 | ||
|
|
975efe3d37 | ||
|
|
87626040ca | ||
|
|
e7d71f95bf | ||
|
|
1d6a9e5763 | ||
|
|
2e9a99fe8f |
@@ -24,6 +24,9 @@ jobs:
|
|||||||
git add VERSION
|
git add VERSION
|
||||||
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
|
git diff --cached --quiet || git commit -m "chore: bump version [skip ci]"
|
||||||
version=$(cat VERSION)
|
version=$(cat VERSION)
|
||||||
|
major="${version%%.*}"
|
||||||
git tag "v${version}"
|
git tag "v${version}"
|
||||||
|
git tag -f "v${major}"
|
||||||
git push
|
git push
|
||||||
git push --tags
|
git push origin "refs/tags/v${version}"
|
||||||
|
git push --force origin "refs/tags/v${major}"
|
||||||
|
|||||||
@@ -1,7 +1,9 @@
|
|||||||
ACTIONS := \
|
ACTIONS := \
|
||||||
docker \
|
docker \
|
||||||
node \
|
node \
|
||||||
|
claude/check-shared-block \
|
||||||
git/create_tag \
|
git/create_tag \
|
||||||
|
git/promotion-gate \
|
||||||
helm/diff \
|
helm/diff \
|
||||||
helm/template \
|
helm/template \
|
||||||
helm/upgrade \
|
helm/upgrade \
|
||||||
|
|||||||
@@ -4,6 +4,12 @@ Reusable composite actions for Gitea CI/CD pipelines.
|
|||||||
|
|
||||||
## Actions
|
## Actions
|
||||||
|
|
||||||
|
### Claude
|
||||||
|
|
||||||
|
| Action | Description |
|
||||||
|
|---|---|
|
||||||
|
| [claude/check-shared-block](claude/check-shared-block/README.md) | Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra |
|
||||||
|
|
||||||
### Docker
|
### Docker
|
||||||
|
|
||||||
| Action | Description |
|
| Action | Description |
|
||||||
@@ -15,6 +21,7 @@ Reusable composite actions for Gitea CI/CD pipelines.
|
|||||||
| Action | Description |
|
| Action | Description |
|
||||||
|---|---|
|
|---|---|
|
||||||
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
|
| [git/create_tag](git/create_tag/README.md) | Create and push a git tag in the current repository |
|
||||||
|
| [git/promotion-gate](git/promotion-gate/README.md) | Enforce which source branches may merge into which target branches |
|
||||||
|
|
||||||
### Helm
|
### Helm
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,44 @@
|
|||||||
|
# Check Shared CLAUDE.md Block
|
||||||
|
|
||||||
|
<!-- action-docs-description source="action.yml" -->
|
||||||
|
## Description
|
||||||
|
|
||||||
|
Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
|
||||||
|
<!-- action-docs-description source="action.yml" -->
|
||||||
|
|
||||||
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
## Inputs
|
||||||
|
|
||||||
|
| name | description | required | default |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| `TARGET` | <p>Path to the CLAUDE.md file to check</p> | `false` | `CLAUDE.md` |
|
||||||
|
| `CANONICAL_URL` | <p>Raw URL of the canonical shared fragment</p> | `false` | `https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md` |
|
||||||
|
| `GITEA_TOKEN` | <p>Gitea token with read access to stat-tackler-infra, if it is private</p> | `false` | `""` |
|
||||||
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
## Runs
|
||||||
|
|
||||||
|
This action is a `composite` action.
|
||||||
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
|
||||||
|
## Running locally
|
||||||
|
|
||||||
|
The check logic has no dependency on the composite action wrapper beyond
|
||||||
|
`curl`, `awk`, and `diff` on `PATH`. From a repo's root:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
CANONICAL_URL=https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md \
|
||||||
|
TARGET=CLAUDE.md sh -c '
|
||||||
|
extract() { awk "/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}" "$1"; }
|
||||||
|
tmp=$(mktemp)
|
||||||
|
curl -sfSL "$CANONICAL_URL" -o "$tmp"
|
||||||
|
extract "$tmp" > "$tmp.canon"
|
||||||
|
extract "$TARGET" > "$tmp.mine"
|
||||||
|
diff -u "$tmp.canon" "$tmp.mine" && echo "matches canonical"
|
||||||
|
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
|
||||||
|
'
|
||||||
|
```
|
||||||
|
|
||||||
|
`GITEA_TOKEN` is only needed if `stat-tackler-infra` becomes private; it is
|
||||||
|
otherwise safe to omit.
|
||||||
@@ -0,0 +1,75 @@
|
|||||||
|
name: Check Shared CLAUDE.md Block
|
||||||
|
description: Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra
|
||||||
|
|
||||||
|
inputs:
|
||||||
|
TARGET:
|
||||||
|
description: "Path to the CLAUDE.md file to check"
|
||||||
|
default: "CLAUDE.md"
|
||||||
|
CANONICAL_URL:
|
||||||
|
description: "Raw URL of the canonical shared fragment"
|
||||||
|
default: "https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md"
|
||||||
|
GITEA_TOKEN:
|
||||||
|
description: "Gitea token with read access to stat-tackler-infra, if it is private"
|
||||||
|
default: ""
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Check shared CLAUDE.md block
|
||||||
|
shell: sh
|
||||||
|
env:
|
||||||
|
TARGET: ${{ inputs.TARGET }}
|
||||||
|
CANONICAL_URL: ${{ inputs.CANONICAL_URL }}
|
||||||
|
GITEA_TOKEN: ${{ inputs.GITEA_TOKEN }}
|
||||||
|
run: |
|
||||||
|
set -e
|
||||||
|
|
||||||
|
if [ ! -f "$TARGET" ]; then
|
||||||
|
echo "::error::$TARGET not found"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
extract() {
|
||||||
|
# Everything between the markers, markers included.
|
||||||
|
awk '/<!-- SHARED:BEGIN/{f=1} f{print} /SHARED:END -->/{f=0}' "$1"
|
||||||
|
}
|
||||||
|
|
||||||
|
mine=$(extract "$TARGET")
|
||||||
|
if [ -z "$mine" ]; then
|
||||||
|
echo "::error::$TARGET has no SHARED:BEGIN/SHARED:END block."
|
||||||
|
echo "Copy it from $CANONICAL_URL"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
tmp=$(mktemp)
|
||||||
|
if [ -n "$GITEA_TOKEN" ]; then
|
||||||
|
curl -sfSL -H "Authorization: token $GITEA_TOKEN" "$CANONICAL_URL" -o "$tmp"
|
||||||
|
else
|
||||||
|
curl -sfSL "$CANONICAL_URL" -o "$tmp"
|
||||||
|
fi
|
||||||
|
|
||||||
|
theirs=$(extract "$tmp")
|
||||||
|
if [ -z "$theirs" ]; then
|
||||||
|
echo "::error::Could not read the canonical block from $CANONICAL_URL"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$mine" = "$theirs" ]; then
|
||||||
|
echo "Shared CLAUDE.md block matches the canonical copy."
|
||||||
|
rm -f "$tmp"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
echo "::error::The shared CLAUDE.md block has drifted from the canonical copy."
|
||||||
|
echo "Canonical: $CANONICAL_URL"
|
||||||
|
echo
|
||||||
|
echo "--- canonical"
|
||||||
|
echo "+++ $TARGET"
|
||||||
|
printf '%s\n' "$theirs" > "$tmp.canon"
|
||||||
|
printf '%s\n' "$mine" > "$tmp.mine"
|
||||||
|
diff -u "$tmp.canon" "$tmp.mine" || true
|
||||||
|
rm -f "$tmp" "$tmp.canon" "$tmp.mine"
|
||||||
|
exit 1
|
||||||
@@ -20,6 +20,7 @@ Build a Docker image and push it to the Gitea container registry
|
|||||||
| `ARTIFACT_NAME` | <p>Name of the build artifact to download</p> | `false` | `dist` |
|
| `ARTIFACT_NAME` | <p>Name of the build artifact to download</p> | `false` | `dist` |
|
||||||
| `ARTIFACT_PATH` | <p>Destination path for the downloaded artifact</p> | `false` | `dist` |
|
| `ARTIFACT_PATH` | <p>Destination path for the downloaded artifact</p> | `false` | `dist` |
|
||||||
| `TAG_LATEST` | <p>Also tag and push the image as latest</p> | `false` | `false` |
|
| `TAG_LATEST` | <p>Also tag and push the image as latest</p> | `false` | `false` |
|
||||||
|
| `TAG_PREFIX` | <p>Optional prefix to prepend to IMAGE_TAG (e.g. 'dev' produces 'dev-<tag>'). Does not affect the latest tag.</p> | `false` | `""` |
|
||||||
| `WORKING_DIRECTORY` | <p>Working directory for the Docker build</p> | `false` | `.` |
|
| `WORKING_DIRECTORY` | <p>Working directory for the Docker build</p> | `false` | `.` |
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
|
|||||||
+8
-1
@@ -28,6 +28,9 @@ inputs:
|
|||||||
TAG_LATEST:
|
TAG_LATEST:
|
||||||
description: "Also tag and push the image as latest"
|
description: "Also tag and push the image as latest"
|
||||||
default: "false"
|
default: "false"
|
||||||
|
TAG_PREFIX:
|
||||||
|
description: "Optional prefix to prepend to IMAGE_TAG (e.g. 'dev' produces 'dev-<tag>'). Does not affect the latest tag."
|
||||||
|
default: ""
|
||||||
WORKING_DIRECTORY:
|
WORKING_DIRECTORY:
|
||||||
description: "Working directory for the Docker build"
|
description: "Working directory for the Docker build"
|
||||||
default: "."
|
default: "."
|
||||||
@@ -51,7 +54,11 @@ runs:
|
|||||||
- name: Docker Build and Push
|
- name: Docker Build and Push
|
||||||
shell: sh
|
shell: sh
|
||||||
run: |
|
run: |
|
||||||
TAGS="-t ${{ inputs.IMAGE_PATH }}:${{ inputs.IMAGE_TAG }}"
|
TAG="${{ inputs.IMAGE_TAG }}"
|
||||||
|
if [ -n "${{ inputs.TAG_PREFIX }}" ]; then
|
||||||
|
TAG="${{ inputs.TAG_PREFIX }}-${TAG}"
|
||||||
|
fi
|
||||||
|
TAGS="-t ${{ inputs.IMAGE_PATH }}:${TAG}"
|
||||||
if [ "${{ inputs.TAG_LATEST }}" = "true" ]; then
|
if [ "${{ inputs.TAG_LATEST }}" = "true" ]; then
|
||||||
TAGS="$TAGS -t ${{ inputs.IMAGE_PATH }}:latest"
|
TAGS="$TAGS -t ${{ inputs.IMAGE_PATH }}:latest"
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
# Promotion Gate
|
||||||
|
|
||||||
|
<!-- action-docs-description source="action.yml" -->
|
||||||
|
## Description
|
||||||
|
|
||||||
|
Enforce which source branches may merge into which target branches
|
||||||
|
<!-- action-docs-description source="action.yml" -->
|
||||||
|
|
||||||
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
## Inputs
|
||||||
|
|
||||||
|
| name | description | required | default |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| `rules` | <p>One rule per line: "target:allowed1,allowed2,…". Targets not listed are unrestricted. Allowed entries may use a trailing glob, e.g. <code>hotfix-*</code>. Leave empty (default) to skip entirely.</p> | `false` | `""` |
|
||||||
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
## Runs
|
||||||
|
|
||||||
|
This action is a `composite` action.
|
||||||
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
@@ -0,0 +1,75 @@
|
|||||||
|
name: Promotion Gate
|
||||||
|
description: Enforce which source branches may merge into which target branches
|
||||||
|
inputs:
|
||||||
|
rules:
|
||||||
|
description: |
|
||||||
|
One rule per line: "target:allowed1,allowed2,...". Targets not
|
||||||
|
listed are unrestricted. Allowed entries may use a trailing glob,
|
||||||
|
e.g. `hotfix-*`. Leave empty (default) to skip entirely.
|
||||||
|
default: ""
|
||||||
|
|
||||||
|
runs:
|
||||||
|
using: composite
|
||||||
|
steps:
|
||||||
|
- name: Check merge source is allowed for target branch
|
||||||
|
shell: sh
|
||||||
|
env:
|
||||||
|
BASE: ${{ gitea.event.pull_request.base.ref }}
|
||||||
|
HEAD: ${{ gitea.event.pull_request.head.ref }}
|
||||||
|
RULES: ${{ inputs.rules }}
|
||||||
|
run: |
|
||||||
|
if [ -z "$RULES" ]; then
|
||||||
|
echo "No promotion rules configured — skipping."
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
rc=0
|
||||||
|
found=0
|
||||||
|
|
||||||
|
oldIFS=$IFS
|
||||||
|
IFS='
|
||||||
|
'
|
||||||
|
set -f
|
||||||
|
set -- $RULES
|
||||||
|
set +f
|
||||||
|
IFS=$oldIFS
|
||||||
|
|
||||||
|
for line in "$@"; do
|
||||||
|
if [ -z "$line" ]; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
target=${line%%:*}
|
||||||
|
allowed=${line#*:}
|
||||||
|
if [ "$target" = "$line" ]; then
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
if [ "$BASE" = "$target" ]; then
|
||||||
|
found=1
|
||||||
|
matched=0
|
||||||
|
innerIFS=$IFS
|
||||||
|
IFS=','
|
||||||
|
for pat in $allowed; do
|
||||||
|
IFS=$innerIFS
|
||||||
|
case "$HEAD" in
|
||||||
|
$pat)
|
||||||
|
matched=1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
IFS=','
|
||||||
|
done
|
||||||
|
IFS=$innerIFS
|
||||||
|
|
||||||
|
if [ "$matched" -eq 1 ]; then
|
||||||
|
echo "Allowed: '$HEAD' -> '$BASE' (matches: $allowed)"
|
||||||
|
else
|
||||||
|
echo "::error::$BASE only accepts merges from: $allowed — got '$HEAD'"
|
||||||
|
rc=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$found" -eq 0 ]; then
|
||||||
|
echo "No promotion-source restriction configured for base '$BASE'"
|
||||||
|
fi
|
||||||
|
|
||||||
|
exit $rc
|
||||||
+9
-7
@@ -11,14 +11,16 @@ Diff a Helm chart for a deployment in a Kubernetes cluster
|
|||||||
|
|
||||||
| name | description | required | default |
|
| name | description | required | default |
|
||||||
| --- | --- | --- | --- |
|
| --- | --- | --- | --- |
|
||||||
| `DEPLOYMENT_NAME` | <p>The Kubernetes Deployment to update</p> | `true` | `""` |
|
| `DEPLOYMENT_NAME` | <p>The Helm release name</p> | `true` | `""` |
|
||||||
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace of the Deployment</p> | `true` | `""` |
|
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace (defaults to DEPLOYMENT_NAME)</p> | `false` | `""` |
|
||||||
| `IMAGE_PATH` | <p>The registry path to the image</p> | `true` | `""` |
|
| `REGISTRY` | <p>OCI registry hostname for helm dependency login</p> | `true` | `""` |
|
||||||
| `IMAGE_TAG` | <p>The image tag to deploy</p> | `true` | `""` |
|
| `REGISTRY_USERNAME` | <p>Username for OCI registry login</p> | `true` | `""` |
|
||||||
| `CONTAINER_NAME` | <p>The container component to update</p> | `true` | `""` |
|
| `REGISTRY_TOKEN` | <p>Token for OCI registry login</p> | `true` | `""` |
|
||||||
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
|
|
||||||
| `CHART_PATH` | <p>Path to the Helm chart</p> | `false` | `./helm` |
|
| `CHART_PATH` | <p>Path to the Helm chart</p> | `false` | `./helm` |
|
||||||
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `true` | `""` |
|
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
|
||||||
|
| `IMAGE_PATH` | <p>The registry path to the image (optional)</p> | `false` | `""` |
|
||||||
|
| `IMAGE_TAG` | <p>The image tag to deploy (optional)</p> | `false` | `""` |
|
||||||
|
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `false` | `""` |
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
|||||||
+50
-16
@@ -2,40 +2,74 @@ name: Helm Diff Deployment
|
|||||||
description: Diff a Helm chart for a deployment in a Kubernetes cluster
|
description: Diff a Helm chart for a deployment in a Kubernetes cluster
|
||||||
inputs:
|
inputs:
|
||||||
DEPLOYMENT_NAME:
|
DEPLOYMENT_NAME:
|
||||||
description: "The Kubernetes Deployment to update"
|
description: "The Helm release name"
|
||||||
required: true
|
required: true
|
||||||
DEPLOYMENT_NAMESPACE:
|
DEPLOYMENT_NAMESPACE:
|
||||||
description: "The Kubernetes namespace of the Deployment"
|
description: "The Kubernetes namespace (defaults to DEPLOYMENT_NAME)"
|
||||||
|
default: ""
|
||||||
|
REGISTRY:
|
||||||
|
description: "OCI registry hostname for helm dependency login"
|
||||||
required: true
|
required: true
|
||||||
IMAGE_PATH:
|
REGISTRY_USERNAME:
|
||||||
description: "The registry path to the image"
|
description: "Username for OCI registry login"
|
||||||
required: true
|
required: true
|
||||||
IMAGE_TAG:
|
REGISTRY_TOKEN:
|
||||||
description: "The image tag to deploy"
|
description: "Token for OCI registry login"
|
||||||
required: true
|
required: true
|
||||||
CONTAINER_NAME:
|
|
||||||
description: "The container component to update"
|
|
||||||
required: true
|
|
||||||
VALUES_FILE:
|
|
||||||
description: "The values file to use"
|
|
||||||
default: "./helm/values.yaml"
|
|
||||||
CHART_PATH:
|
CHART_PATH:
|
||||||
description: "Path to the Helm chart"
|
description: "Path to the Helm chart"
|
||||||
default: "./helm"
|
default: "./helm"
|
||||||
|
VALUES_FILE:
|
||||||
|
description: "The values file to use"
|
||||||
|
default: "./helm/values.yaml"
|
||||||
|
IMAGE_PATH:
|
||||||
|
description: "The registry path to the image (optional)"
|
||||||
|
default: ""
|
||||||
|
IMAGE_TAG:
|
||||||
|
description: "The image tag to deploy (optional)"
|
||||||
|
default: ""
|
||||||
TAG_KEY:
|
TAG_KEY:
|
||||||
description: "Helm --set key for the image tag (e.g. deploy.api.tag)"
|
description: "Helm --set key for the image tag (e.g. deploy.api.tag)"
|
||||||
required: true
|
default: ""
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
steps:
|
steps:
|
||||||
|
- name: Helm OCI Login
|
||||||
|
shell: sh
|
||||||
|
env:
|
||||||
|
REGISTRY: ${{ inputs.REGISTRY }}
|
||||||
|
REGISTRY_USERNAME: ${{ inputs.REGISTRY_USERNAME }}
|
||||||
|
REGISTRY_TOKEN: ${{ inputs.REGISTRY_TOKEN }}
|
||||||
|
run: |
|
||||||
|
echo "$REGISTRY_TOKEN" | helm registry login "$REGISTRY" \
|
||||||
|
--username "$REGISTRY_USERNAME" \
|
||||||
|
--password-stdin
|
||||||
|
|
||||||
- name: Install Helm Diff
|
- name: Install Helm Diff
|
||||||
shell: sh
|
shell: sh
|
||||||
run: |
|
run: |
|
||||||
helm plugin list | grep -q diff || helm plugin install https://github.com/databus23/helm-diff
|
helm plugin list | grep -q diff || helm plugin install https://github.com/databus23/helm-diff
|
||||||
|
|
||||||
- name: Helm Diff
|
- name: Helm Diff
|
||||||
shell: sh
|
shell: sh
|
||||||
|
env:
|
||||||
|
DEPLOYMENT_NAME: ${{ inputs.DEPLOYMENT_NAME }}
|
||||||
|
DEPLOYMENT_NAMESPACE: ${{ inputs.DEPLOYMENT_NAMESPACE }}
|
||||||
|
CHART_PATH: ${{ inputs.CHART_PATH }}
|
||||||
|
VALUES_FILE: ${{ inputs.VALUES_FILE }}
|
||||||
|
IMAGE_PATH: ${{ inputs.IMAGE_PATH }}
|
||||||
|
IMAGE_TAG: ${{ inputs.IMAGE_TAG }}
|
||||||
|
TAG_KEY: ${{ inputs.TAG_KEY }}
|
||||||
run: |
|
run: |
|
||||||
CMD="helm diff upgrade ${{ inputs.DEPLOYMENT_NAME }} ${{ inputs.CHART_PATH }} -n ${{ inputs.DEPLOYMENT_NAMESPACE }} --values ${{ inputs.VALUES_FILE }} --set ${TAG_KEY}=${{ inputs.IMAGE_TAG }} --set image.repository=${{ inputs.IMAGE_PATH }} --context 5"
|
NAMESPACE="$DEPLOYMENT_NAMESPACE"
|
||||||
echo "Running: $CMD"
|
if [ -z "$NAMESPACE" ]; then NAMESPACE="$DEPLOYMENT_NAME"; fi
|
||||||
eval "$CMD"
|
SET_FLAGS=""
|
||||||
|
if [ -n "$TAG_KEY" ] && [ -n "$IMAGE_TAG" ]; then
|
||||||
|
SET_FLAGS="$SET_FLAGS --set $TAG_KEY=$IMAGE_TAG"
|
||||||
|
fi
|
||||||
|
if [ -n "$IMAGE_PATH" ]; then
|
||||||
|
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
|
||||||
|
fi
|
||||||
|
helm dependency update "$CHART_PATH"
|
||||||
|
helm diff upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS --context 5
|
||||||
|
|||||||
@@ -11,14 +11,16 @@ Template a Helm chart for a deployment in a Kubernetes cluster
|
|||||||
|
|
||||||
| name | description | required | default |
|
| name | description | required | default |
|
||||||
| --- | --- | --- | --- |
|
| --- | --- | --- | --- |
|
||||||
| `DEPLOYMENT_NAME` | <p>The Kubernetes Deployment to update</p> | `true` | `""` |
|
| `DEPLOYMENT_NAME` | <p>The Helm release name</p> | `true` | `""` |
|
||||||
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace of the Deployment</p> | `true` | `""` |
|
| `DEPLOYMENT_NAMESPACE` | <p>The Kubernetes namespace (defaults to DEPLOYMENT_NAME)</p> | `false` | `""` |
|
||||||
| `IMAGE_PATH` | <p>The registry path to the image</p> | `true` | `""` |
|
| `REGISTRY` | <p>OCI registry hostname for helm dependency login</p> | `true` | `""` |
|
||||||
| `IMAGE_TAG` | <p>The image tag to deploy</p> | `true` | `""` |
|
| `REGISTRY_USERNAME` | <p>Username for OCI registry login</p> | `true` | `""` |
|
||||||
| `CONTAINER_NAME` | <p>The container component to update</p> | `true` | `""` |
|
| `REGISTRY_TOKEN` | <p>Token for OCI registry login</p> | `true` | `""` |
|
||||||
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
|
|
||||||
| `CHART_PATH` | <p>Path to the Helm chart</p> | `false` | `./helm` |
|
| `CHART_PATH` | <p>Path to the Helm chart</p> | `false` | `./helm` |
|
||||||
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `true` | `""` |
|
| `VALUES_FILE` | <p>The values file to use</p> | `false` | `./helm/values.yaml` |
|
||||||
|
| `IMAGE_PATH` | <p>The registry path to the image (optional)</p> | `false` | `""` |
|
||||||
|
| `IMAGE_TAG` | <p>The image tag to deploy (optional)</p> | `false` | `""` |
|
||||||
|
| `TAG_KEY` | <p>Helm --set key for the image tag (e.g. deploy.api.tag)</p> | `false` | `""` |
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
|||||||
+49
-16
@@ -2,36 +2,69 @@ name: Helm Template Deployment
|
|||||||
description: Template a Helm chart for a deployment in a Kubernetes cluster
|
description: Template a Helm chart for a deployment in a Kubernetes cluster
|
||||||
inputs:
|
inputs:
|
||||||
DEPLOYMENT_NAME:
|
DEPLOYMENT_NAME:
|
||||||
description: "The Kubernetes Deployment to update"
|
description: "The Helm release name"
|
||||||
required: true
|
required: true
|
||||||
DEPLOYMENT_NAMESPACE:
|
DEPLOYMENT_NAMESPACE:
|
||||||
description: "The Kubernetes namespace of the Deployment"
|
description: "The Kubernetes namespace (defaults to DEPLOYMENT_NAME)"
|
||||||
|
default: ""
|
||||||
|
REGISTRY:
|
||||||
|
description: "OCI registry hostname for helm dependency login"
|
||||||
required: true
|
required: true
|
||||||
IMAGE_PATH:
|
REGISTRY_USERNAME:
|
||||||
description: "The registry path to the image"
|
description: "Username for OCI registry login"
|
||||||
required: true
|
required: true
|
||||||
IMAGE_TAG:
|
REGISTRY_TOKEN:
|
||||||
description: "The image tag to deploy"
|
description: "Token for OCI registry login"
|
||||||
required: true
|
required: true
|
||||||
CONTAINER_NAME:
|
|
||||||
description: "The container component to update"
|
|
||||||
required: true
|
|
||||||
VALUES_FILE:
|
|
||||||
description: "The values file to use"
|
|
||||||
default: "./helm/values.yaml"
|
|
||||||
CHART_PATH:
|
CHART_PATH:
|
||||||
description: "Path to the Helm chart"
|
description: "Path to the Helm chart"
|
||||||
default: "./helm"
|
default: "./helm"
|
||||||
|
VALUES_FILE:
|
||||||
|
description: "The values file to use"
|
||||||
|
default: "./helm/values.yaml"
|
||||||
|
IMAGE_PATH:
|
||||||
|
description: "The registry path to the image (optional)"
|
||||||
|
default: ""
|
||||||
|
IMAGE_TAG:
|
||||||
|
description: "The image tag to deploy (optional)"
|
||||||
|
default: ""
|
||||||
TAG_KEY:
|
TAG_KEY:
|
||||||
description: "Helm --set key for the image tag (e.g. deploy.api.tag)"
|
description: "Helm --set key for the image tag (e.g. deploy.api.tag)"
|
||||||
required: true
|
default: ""
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
steps:
|
steps:
|
||||||
|
- name: Helm OCI Login
|
||||||
|
shell: sh
|
||||||
|
env:
|
||||||
|
REGISTRY: ${{ inputs.REGISTRY }}
|
||||||
|
REGISTRY_USERNAME: ${{ inputs.REGISTRY_USERNAME }}
|
||||||
|
REGISTRY_TOKEN: ${{ inputs.REGISTRY_TOKEN }}
|
||||||
|
run: |
|
||||||
|
echo "$REGISTRY_TOKEN" | helm registry login "$REGISTRY" \
|
||||||
|
--username "$REGISTRY_USERNAME" \
|
||||||
|
--password-stdin
|
||||||
|
|
||||||
- name: Helm Template
|
- name: Helm Template
|
||||||
shell: sh
|
shell: sh
|
||||||
|
env:
|
||||||
|
DEPLOYMENT_NAME: ${{ inputs.DEPLOYMENT_NAME }}
|
||||||
|
DEPLOYMENT_NAMESPACE: ${{ inputs.DEPLOYMENT_NAMESPACE }}
|
||||||
|
CHART_PATH: ${{ inputs.CHART_PATH }}
|
||||||
|
VALUES_FILE: ${{ inputs.VALUES_FILE }}
|
||||||
|
IMAGE_PATH: ${{ inputs.IMAGE_PATH }}
|
||||||
|
IMAGE_TAG: ${{ inputs.IMAGE_TAG }}
|
||||||
|
TAG_KEY: ${{ inputs.TAG_KEY }}
|
||||||
run: |
|
run: |
|
||||||
CMD="helm template ${{ inputs.DEPLOYMENT_NAME }} ${{ inputs.CHART_PATH }} -n ${{ inputs.DEPLOYMENT_NAMESPACE }} --values ${{ inputs.VALUES_FILE }} --set ${TAG_KEY}=${{ inputs.IMAGE_TAG }} --set image.repository=${{ inputs.IMAGE_PATH }}"
|
NAMESPACE="$DEPLOYMENT_NAMESPACE"
|
||||||
echo "Running: $CMD"
|
if [ -z "$NAMESPACE" ]; then NAMESPACE="$DEPLOYMENT_NAME"; fi
|
||||||
eval "$CMD"
|
SET_FLAGS=""
|
||||||
|
if [ -n "$TAG_KEY" ] && [ -n "$IMAGE_TAG" ]; then
|
||||||
|
SET_FLAGS="$SET_FLAGS --set $TAG_KEY=$IMAGE_TAG"
|
||||||
|
fi
|
||||||
|
if [ -n "$IMAGE_PATH" ]; then
|
||||||
|
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
|
||||||
|
fi
|
||||||
|
helm dependency update "$CHART_PATH"
|
||||||
|
helm template "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
|
||||||
|
|||||||
@@ -67,7 +67,6 @@ runs:
|
|||||||
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
|
SET_FLAGS="$SET_FLAGS --set image.repository=$IMAGE_PATH"
|
||||||
fi
|
fi
|
||||||
helm dependency update "$CHART_PATH"
|
helm dependency update "$CHART_PATH"
|
||||||
echo "Running: helm upgrade $DEPLOYMENT_NAME $CHART_PATH -n $NAMESPACE --values $VALUES_FILE$SET_FLAGS"
|
|
||||||
helm upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
|
helm upgrade "$DEPLOYMENT_NAME" "$CHART_PATH" -n "$NAMESPACE" --values "$VALUES_FILE" $SET_FLAGS
|
||||||
|
|
||||||
- name: Remove kubeconfig
|
- name: Remove kubeconfig
|
||||||
|
|||||||
@@ -38,5 +38,9 @@ runs:
|
|||||||
git config user.email "gitea-actions@gitea.pixelparasol.com"
|
git config user.email "gitea-actions@gitea.pixelparasol.com"
|
||||||
git config user.name "Gitea Actions"
|
git config user.name "Gitea Actions"
|
||||||
git add releases/versions.yaml
|
git add releases/versions.yaml
|
||||||
|
if git diff --cached --quiet; then
|
||||||
|
echo "No version change for ${{ inputs.service }}, skipping commit"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
git commit -m "chore: update ${{ inputs.service }} to ${{ inputs.tag }}"
|
git commit -m "chore: update ${{ inputs.service }} to ${{ inputs.tag }}"
|
||||||
git push
|
git push
|
||||||
|
|||||||
@@ -18,6 +18,7 @@ Install dependencies, build, and upload a build artifact
|
|||||||
| `ARTIFACT_PATH` | <p>Path to upload as the artifact</p> | `false` | `dist` |
|
| `ARTIFACT_PATH` | <p>Path to upload as the artifact</p> | `false` | `dist` |
|
||||||
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
|
||||||
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
|
||||||
|
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
|
||||||
<!-- action-docs-inputs source="action.yml" -->
|
<!-- action-docs-inputs source="action.yml" -->
|
||||||
|
|
||||||
<!-- action-docs-runs source="action.yml" -->
|
<!-- action-docs-runs source="action.yml" -->
|
||||||
|
|||||||
@@ -22,6 +22,9 @@ inputs:
|
|||||||
WORKING_DIRECTORY:
|
WORKING_DIRECTORY:
|
||||||
description: "Working directory for install, build, and artifact steps"
|
description: "Working directory for install, build, and artifact steps"
|
||||||
default: "."
|
default: "."
|
||||||
|
UPLOAD_ARTIFACT:
|
||||||
|
description: "Whether to upload the build artifact"
|
||||||
|
default: "true"
|
||||||
|
|
||||||
runs:
|
runs:
|
||||||
using: composite
|
using: composite
|
||||||
@@ -56,6 +59,7 @@ runs:
|
|||||||
cp node_modules/.prisma/client/libquery_engine-* build/prisma/
|
cp node_modules/.prisma/client/libquery_engine-* build/prisma/
|
||||||
|
|
||||||
- name: Upload Build Artifact
|
- name: Upload Build Artifact
|
||||||
|
if: inputs.UPLOAD_ARTIFACT != 'false'
|
||||||
uses: actions/upload-artifact@v3
|
uses: actions/upload-artifact@v3
|
||||||
with:
|
with:
|
||||||
name: ${{ inputs.ARTIFACT_NAME }}
|
name: ${{ inputs.ARTIFACT_NAME }}
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ Composite action: install dependencies and run an npm test script.
|
|||||||
|---|---|---|
|
|---|---|---|
|
||||||
| `INSTALL_CMD` | Install command | `npm ci` |
|
| `INSTALL_CMD` | Install command | `npm ci` |
|
||||||
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
|
||||||
|
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
|
||||||
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
@@ -18,6 +19,15 @@ Composite action: install dependencies and run an npm test script.
|
|||||||
TEST_SCRIPT: test:unit
|
TEST_SCRIPT: test:unit
|
||||||
```
|
```
|
||||||
|
|
||||||
|
With extra args:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
- uses: stat-tackler/stat-tackler-infra/test/npm@main
|
||||||
|
with:
|
||||||
|
TEST_SCRIPT: test:coverage
|
||||||
|
TEST_ARGS: --silent --reporter=dot --test-timeout=30000
|
||||||
|
```
|
||||||
|
|
||||||
### Common test scripts by project
|
### Common test scripts by project
|
||||||
|
|
||||||
| Project | Script | Runner |
|
| Project | Script | Runner |
|
||||||
|
|||||||
+4
-1
@@ -8,6 +8,9 @@ inputs:
|
|||||||
TEST_SCRIPT:
|
TEST_SCRIPT:
|
||||||
description: "npm script to run (must exist in package.json)"
|
description: "npm script to run (must exist in package.json)"
|
||||||
default: "test"
|
default: "test"
|
||||||
|
TEST_ARGS:
|
||||||
|
description: "Additional arguments to pass after -- to the test script"
|
||||||
|
default: ""
|
||||||
WORKING_DIRECTORY:
|
WORKING_DIRECTORY:
|
||||||
description: "Directory to run commands in"
|
description: "Directory to run commands in"
|
||||||
default: "."
|
default: "."
|
||||||
@@ -37,4 +40,4 @@ runs:
|
|||||||
- name: Test
|
- name: Test
|
||||||
shell: sh
|
shell: sh
|
||||||
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
working-directory: ${{ inputs.WORKING_DIRECTORY }}
|
||||||
run: npm run ${{ inputs.TEST_SCRIPT }}
|
run: npm run ${{ inputs.TEST_SCRIPT }}${{ inputs.TEST_ARGS != '' && format(' -- {0}', inputs.TEST_ARGS) || '' }}
|
||||||
|
|||||||
Reference in New Issue
Block a user