Skip to content

chore(deps): update cloudnative-pg/grafana-dashboards digest to e74d67f #743

chore(deps): update cloudnative-pg/grafana-dashboards digest to e74d67f

chore(deps): update cloudnative-pg/grafana-dashboards digest to e74d67f #743

Workflow file for this run

name: Validate Manifests
on:
pull_request:
branches: [main]
env:
# renovate: datasource=github-releases depName=yannh/kubeconform
KUBECONFORM_VERSION: v0.8.0
# CRD schemas (IngressRoute, Middleware, CNPG Cluster, Application,
# PodMonitor, ...). Without this, kubeconform skips every CRD-typed
# resource — more than half the repo — while reporting green.
CRD_SCHEMAS: 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{ .Group }}/{{ .ResourceKind }}_{{ .ResourceAPIVersion }}.json'
jobs:
yaml-lint:
name: YAML Lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Install yamllint
run: pip install yamllint
- name: Lint YAML files
run: |
yamllint -d '{extends: relaxed, rules: {line-length: {max: 200}}}' \
manifests/ bootstrap/
security-txt:
name: Validate security.txt
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Validate signed security.txt
run: .github/scripts/validate-security-txt.sh
ksops-checksum:
name: Verify ksops pinned hash
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
# Renovate bumps KSOPS_VERSION but cannot compute the new tarball's
# sha256 — this job keeps a version/hash mismatch from ever merging.
- name: Embedded KSOPS_SHA256 matches upstream checksums.txt
run: |
PATCH=bootstrap/argocd/repo-server-ksops-patch.yaml
VERSION=$(grep -oP 'KSOPS_VERSION=\K[0-9][0-9.]*' "$PATCH")
EMBEDDED=$(grep -oP 'KSOPS_SHA256=\K[a-f0-9]{64}' "$PATCH")
UPSTREAM=$(curl -fsSL "https://github.com/viaduct-ai/kustomize-sops/releases/download/v${VERSION}/checksums.txt" \
| grep -F " ksops_${VERSION}_Linux_x86_64.tar.gz" | awk '{print $1}')
echo "version=${VERSION} embedded=${EMBEDDED} upstream=${UPSTREAM}"
test -n "$UPSTREAM"
test "$EMBEDDED" = "$UPSTREAM"
helm-template:
name: Helm Template Check
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Setup Helm
uses: azure/setup-helm@v5
- name: Render app-of-apps chart
run: helm template sharkshere-apps apps/ --namespace argocd
helm-values:
name: Render Charts With Values
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Setup Helm
uses: azure/setup-helm@v5
# Renders every upstream chart at its pinned version with the exact
# values ArgoCD will pass it. Catches chart/values schema breaks
# (e.g. traefik 41.x rejecting the `logs` key) that rendering only
# the Application envelopes cannot.
- name: Render all charts with their inline values
run: .github/scripts/validate-helm-values.sh
kubeconform:
name: Validate Kubernetes Schemas
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Install kubeconform
run: |
curl -fsSL "https://github.com/yannh/kubeconform/releases/download/${KUBECONFORM_VERSION}/kubeconform-linux-amd64.tar.gz" \
| tar xz -C /usr/local/bin
- name: Validate manifests
run: |
kubeconform -strict -summary -output text \
-ignore-missing-schemas \
-schema-location default \
-schema-location "$CRD_SCHEMAS" \
manifests/
- name: Validate bootstrap manifests
run: |
kubeconform -strict -summary -output text \
-ignore-missing-schemas \
-schema-location default \
-schema-location "$CRD_SCHEMAS" \
bootstrap/argocd-namespace.yaml \
bootstrap/argocd-project.yaml \
bootstrap/root-app.yaml
# The argocd overlay (upstream install + KSOPS/config patches) was
# previously never built in CI, so a broken strategic-merge patch
# merged green and only failed at kubectl-apply time.
- name: Build and validate bootstrap/argocd kustomize overlay
run: |
kubectl kustomize bootstrap/argocd/ \
| kubeconform -strict -summary -output text \
-ignore-missing-schemas \
-schema-location default \
-schema-location "$CRD_SCHEMAS" \
-
helm-kubeconform:
name: Validate Rendered Helm Output
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- name: Setup Helm
uses: azure/setup-helm@v5
- name: Install kubeconform
run: |
curl -fsSL "https://github.com/yannh/kubeconform/releases/download/${KUBECONFORM_VERSION}/kubeconform-linux-amd64.tar.gz" \
| tar xz -C /usr/local/bin
- name: Template and validate
run: |
helm template sharkshere-apps apps/ --namespace argocd \
| kubeconform -strict -summary -output text \
-ignore-missing-schemas \
-schema-location default \
-schema-location "$CRD_SCHEMAS" \
-