chore(deps): update cloudnative-pg/grafana-dashboards digest to e74d67f #743
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Validate Manifests | |
| on: | |
| pull_request: | |
| branches: [main] | |
| env: | |
| # renovate: datasource=github-releases depName=yannh/kubeconform | |
| KUBECONFORM_VERSION: v0.8.0 | |
| # CRD schemas (IngressRoute, Middleware, CNPG Cluster, Application, | |
| # PodMonitor, ...). Without this, kubeconform skips every CRD-typed | |
| # resource — more than half the repo — while reporting green. | |
| CRD_SCHEMAS: 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{ .Group }}/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json' | |
| jobs: | |
| yaml-lint: | |
| name: YAML Lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Install yamllint | |
| run: pip install yamllint | |
| - name: Lint YAML files | |
| run: | | |
| yamllint -d '{extends: relaxed, rules: {line-length: {max: 200}}}' \ | |
| manifests/ bootstrap/ | |
| security-txt: | |
| name: Validate security.txt | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Validate signed security.txt | |
| run: .github/scripts/validate-security-txt.sh | |
| ksops-checksum: | |
| name: Verify ksops pinned hash | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| # Renovate bumps KSOPS_VERSION but cannot compute the new tarball's | |
| # sha256 — this job keeps a version/hash mismatch from ever merging. | |
| - name: Embedded KSOPS_SHA256 matches upstream checksums.txt | |
| run: | | |
| PATCH=bootstrap/argocd/repo-server-ksops-patch.yaml | |
| VERSION=$(grep -oP 'KSOPS_VERSION=\K[0-9][0-9.]*' "$PATCH") | |
| EMBEDDED=$(grep -oP 'KSOPS_SHA256=\K[a-f0-9]{64}' "$PATCH") | |
| UPSTREAM=$(curl -fsSL "https://github.com/viaduct-ai/kustomize-sops/releases/download/v${VERSION}/checksums.txt" \ | |
| | grep -F " ksops_${VERSION}_Linux_x86_64.tar.gz" | awk '{print $1}') | |
| echo "version=${VERSION} embedded=${EMBEDDED} upstream=${UPSTREAM}" | |
| test -n "$UPSTREAM" | |
| test "$EMBEDDED" = "$UPSTREAM" | |
| helm-template: | |
| name: Helm Template Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Helm | |
| uses: azure/setup-helm@v5 | |
| - name: Render app-of-apps chart | |
| run: helm template sharkshere-apps apps/ --namespace argocd | |
| helm-values: | |
| name: Render Charts With Values | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Helm | |
| uses: azure/setup-helm@v5 | |
| # Renders every upstream chart at its pinned version with the exact | |
| # values ArgoCD will pass it. Catches chart/values schema breaks | |
| # (e.g. traefik 41.x rejecting the `logs` key) that rendering only | |
| # the Application envelopes cannot. | |
| - name: Render all charts with their inline values | |
| run: .github/scripts/validate-helm-values.sh | |
| kubeconform: | |
| name: Validate Kubernetes Schemas | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Install kubeconform | |
| run: | | |
| curl -fsSL "https://github.com/yannh/kubeconform/releases/download/${KUBECONFORM_VERSION}/kubeconform-linux-amd64.tar.gz" \ | |
| | tar xz -C /usr/local/bin | |
| - name: Validate manifests | |
| run: | | |
| kubeconform -strict -summary -output text \ | |
| -ignore-missing-schemas \ | |
| -schema-location default \ | |
| -schema-location "$CRD_SCHEMAS" \ | |
| manifests/ | |
| - name: Validate bootstrap manifests | |
| run: | | |
| kubeconform -strict -summary -output text \ | |
| -ignore-missing-schemas \ | |
| -schema-location default \ | |
| -schema-location "$CRD_SCHEMAS" \ | |
| bootstrap/argocd-namespace.yaml \ | |
| bootstrap/argocd-project.yaml \ | |
| bootstrap/root-app.yaml | |
| # The argocd overlay (upstream install + KSOPS/config patches) was | |
| # previously never built in CI, so a broken strategic-merge patch | |
| # merged green and only failed at kubectl-apply time. | |
| - name: Build and validate bootstrap/argocd kustomize overlay | |
| run: | | |
| kubectl kustomize bootstrap/argocd/ \ | |
| | kubeconform -strict -summary -output text \ | |
| -ignore-missing-schemas \ | |
| -schema-location default \ | |
| -schema-location "$CRD_SCHEMAS" \ | |
| - | |
| helm-kubeconform: | |
| name: Validate Rendered Helm Output | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Setup Helm | |
| uses: azure/setup-helm@v5 | |
| - name: Install kubeconform | |
| run: | | |
| curl -fsSL "https://github.com/yannh/kubeconform/releases/download/${KUBECONFORM_VERSION}/kubeconform-linux-amd64.tar.gz" \ | |
| | tar xz -C /usr/local/bin | |
| - name: Template and validate | |
| run: | | |
| helm template sharkshere-apps apps/ --namespace argocd \ | |
| | kubeconform -strict -summary -output text \ | |
| -ignore-missing-schemas \ | |
| -schema-location default \ | |
| -schema-location "$CRD_SCHEMAS" \ | |
| - |