7686581adc
Release / Release (push) Successful in 4s
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [actions/checkout](https://github.com/actions/checkout) | action | major | `v6.0.3` → `v7.0.0` | --- ### Release Notes <details> <summary>actions/checkout (actions/checkout)</summary> ### [`v7.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://github.com/actions/checkout/compare/v7.0.0...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2454](https://github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2458](https://github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2460](https://github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2461](https://github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://github.com/actions/core) and [@​actions/tool-cache](https://github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2459](https://github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2463](https://github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2462](https://github.com/actions/checkout/pull/2462) ### [`v7`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700) [Compare Source](https://github.com/actions/checkout/compare/v6.0.3...v7.0.0) - Block checking out fork PR for pull\_request\_target and workflow\_run by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2454](https://github.com/actions/checkout/pull/2454) - Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2458](https://github.com/actions/checkout/pull/2458) - Bump flatted from 3.3.1 to 3.4.2 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2460](https://github.com/actions/checkout/pull/2460) - Bump js-yaml from 4.1.0 to 4.2.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2461](https://github.com/actions/checkout/pull/2461) - Bump [@​actions/core](https://github.com/actions/core) and [@​actions/tool-cache](https://github.com/actions/tool-cache) and Remove uuid by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2459](https://github.com/actions/checkout/pull/2459) - upgrade module to esm and update dependencies by [@​aiqiaoy](https://github.com/aiqiaoy) in [#​2463](https://github.com/actions/checkout/pull/2463) - Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@​dependabot](https://github.com/dependabot)\[bot] in [#​2462](https://github.com/actions/checkout/pull/2462) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yMzMuNCIsInVwZGF0ZWRJblZlciI6IjQzLjIzMy40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhY3Rpb24iLCJhdXRvbWVyZ2UiLCJkZXBzIl19--> Reviewed-on: #64 Co-authored-by: Renovate Bot <renovate@t00n.de> Co-committed-by: Renovate Bot <renovate@t00n.de>
136 lines
5.5 KiB
YAML
136 lines
5.5 KiB
YAML
name: CI
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
k8s_dir:
|
|
description: "Path to Kubernetes manifests directory"
|
|
required: false
|
|
default: "k8s/"
|
|
type: string
|
|
helmfile_path:
|
|
description: "Path to helmfile.yaml"
|
|
required: false
|
|
default: "helmfile.yaml"
|
|
type: string
|
|
skip_helm_validation:
|
|
description: "Skip Helm validation even if helmfile.yaml exists"
|
|
required: false
|
|
default: false
|
|
type: boolean
|
|
helmfile_env:
|
|
description: "Optional JSON object string of environment variables for Helmfile"
|
|
required: false
|
|
default: "{}"
|
|
type: string
|
|
namespace:
|
|
description: "Override the default namespace (extracted from repository name)"
|
|
required: false
|
|
default: ""
|
|
type: string
|
|
|
|
jobs:
|
|
detect-service-type:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
has_helmfile: ${{ steps.check-helmfile.outputs.exists }}
|
|
has_k8s: ${{ steps.check-k8s.outputs.exists }}
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
- name: Check if helmfile.yaml exists
|
|
id: check-helmfile
|
|
run: |
|
|
if [ -f "${{ inputs.helmfile_path }}" ]; then
|
|
echo "exists=true" >> $GITHUB_OUTPUT
|
|
echo "Found helmfile.yaml at ${{ inputs.helmfile_path }}"
|
|
else
|
|
echo "exists=false" >> $GITHUB_OUTPUT
|
|
echo "No helmfile.yaml found at ${{ inputs.helmfile_path }}"
|
|
fi
|
|
- name: Check if k8s directory exists
|
|
id: check-k8s
|
|
run: |
|
|
if [ -d "${{ inputs.k8s_dir }}" ]; then
|
|
echo "exists=true" >> $GITHUB_OUTPUT
|
|
echo "Found k8s directory at ${{ inputs.k8s_dir }}"
|
|
else
|
|
echo "exists=false" >> $GITHUB_OUTPUT
|
|
echo "No k8s directory found at ${{ inputs.k8s_dir }}"
|
|
fi
|
|
|
|
validate-k8s:
|
|
runs-on: ubuntu-latest
|
|
needs: detect-service-type
|
|
if: needs.detect-service-type.outputs.has_k8s == 'true'
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@244a64884838c35a5fc0dc42e0b82bb70b253dfc # 0.0.1
|
|
id: namespace
|
|
with:
|
|
repo: ${{ github.repository }}
|
|
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
|
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
|
with:
|
|
method: kubeconfig
|
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
- name: Validate k8s manifests
|
|
uses: azure/k8s-lint@e4234c50ea835112e72b145bdecd00a94bad42fd # v4.0.0
|
|
with:
|
|
namespace: ${{ inputs.namespace || steps.namespace.outputs.namespace }}
|
|
lintType: dryrun
|
|
manifests: "${{ inputs.k8s_dir }}"
|
|
|
|
validate-helm:
|
|
runs-on: ubuntu-latest
|
|
needs: detect-service-type
|
|
if: |
|
|
needs.detect-service-type.outputs.has_helmfile == 'true' &&
|
|
needs.detect-service-type.outputs.has_k8s == 'true' &&
|
|
inputs.skip_helm_validation != 'true'
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
- uses: https://gitea.t000-n.de/t.behrendt/k_deploy_actions/.gitea/actions/extract-namespace-from-repo-name@244a64884838c35a5fc0dc42e0b82bb70b253dfc # 0.0.1
|
|
id: namespace
|
|
with:
|
|
repo: ${{ github.repository }}
|
|
- uses: azure/setup-kubectl@829323503d1be3d00ca8346e5391ca0b07a9ab0d # v5.1.0
|
|
- uses: azure/setup-helm@dda3372f752e03dde6b3237bc9431cdc2f7a02a2 # v5
|
|
- uses: azure/k8s-set-context@89b837d75b40a7bd2ddafde837473c212db8b313 # v5.0.0
|
|
with:
|
|
method: kubeconfig
|
|
kubeconfig: ${{ secrets.KUBECONFIG }}
|
|
- name: Validate Helm
|
|
uses: helmfile/helmfile-action@daefb3e1fa5a91b7a88d30870d20da4896944818 # v2.4.5
|
|
with:
|
|
helmfile-args: diff
|
|
namespace: ${{ inputs.namespace || steps.namespace.outputs.namespace }}
|
|
env: ${{ fromJSON(inputs.helmfile_env) }}
|
|
|
|
# Summary job that always runs to show what was validated
|
|
ci-summary:
|
|
runs-on: ubuntu-latest
|
|
needs: [detect-service-type, validate-k8s, validate-helm]
|
|
if: always()
|
|
steps:
|
|
- name: CI Summary
|
|
run: |
|
|
echo "## CI Validation Summary" >> $GITHUB_STEP_SUMMARY
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
|
|
if [ "${{ needs.detect-service-type.outputs.has_k8s }}" == "true" ]; then
|
|
echo "✅ **Kubernetes validation**: Completed" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "❌ **Kubernetes validation**: Skipped (no k8s/ directory found)" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
if [ "${{ needs.detect-service-type.outputs.has_helmfile }}" == "true" ] && [ "${{ inputs.skip_helm_validation }}" != "true" ]; then
|
|
echo "✅ **Helm validation**: Completed" >> $GITHUB_STEP_SUMMARY
|
|
elif [ "${{ needs.detect-service-type.outputs.has_helmfile }}" == "true" ] && [ "${{ inputs.skip_helm_validation }}" == "true" ]; then
|
|
echo "⏭️ **Helm validation**: Skipped (manually disabled)" >> $GITHUB_STEP_SUMMARY
|
|
else
|
|
echo "⏭️ **Helm validation**: Skipped (no helmfile.yaml found)" >> $GITHUB_STEP_SUMMARY
|
|
fi
|
|
|
|
echo "" >> $GITHUB_STEP_SUMMARY
|
|
echo "**Service Type**: ${{ needs.detect-service-type.outputs.has_helmfile == 'true' && 'Helm + Kubernetes' || 'Kubernetes Only' }}" >> $GITHUB_STEP_SUMMARY
|