372fbe0660
CI / test (push) Failing after 1s
Confirmed the hard way (run 852, attempt 2): setup-envtest v0.25 fetches the envtest kube-apiserver/etcd tarball from github.com's release CDN, not the legacy GCS kubebuilder-tools bucket (that bucket 403s now for any object -- no fallback there for k8s 1.37 either). github.com is unreachable from this job's container the same way terdut-server's ci.yaml already documents for get.helm.sh -- TLS handshake timeout. Dropping `container:` on this job is the same fix terdut-server's `chart` job already uses for that exact class of problem (it reaches get.helm.sh only by running on the host). Unproven for a Go job specifically -- no workflow in this org has run Go outside a container before, so this also bets the runner host has Go installed. If it fails on a missing `go` instead of the envtest fetch, that bet was wrong and the real fix is allowlisting github.com's release CDN on the runner's NetworkPolicy instead (Ryuvia/charts or Ryuvia/k8s, outside this repo).
71 lines
3.1 KiB
YAML
71 lines
3.1 KiB
YAML
name: CI
|
|
|
|
# Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is
|
|
# late, so this runs the same checks on the way in instead.
|
|
#
|
|
# push is scoped to main rather than all branches so a branch pushed as part of a pull
|
|
# request is not checked twice.
|
|
#
|
|
# No actions/checkout, deliberately -- same reason as terdut-server: the runner image's
|
|
# `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4
|
|
# dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git
|
|
# directly avoids JS actions entirely. This repo is public, so the clone needs no
|
|
# credential.
|
|
#
|
|
# `${{ }}` values are passed through `env:` and referenced as quoted shell variables --
|
|
# a ref name is attacker-influenced by anyone who can push a branch or open a PR.
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
concurrency:
|
|
group: ci-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git
|
|
|
|
jobs:
|
|
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
|
|
# and a green working copy mean the same thing by construction. `test` also drives
|
|
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
|
|
# chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases
|
|
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket
|
|
# 403s now, confirmed 2026-09-30, no fallback there for k8s 1.37).
|
|
#
|
|
# Confirmed the hard way: running this in `container: golang:1.26.6-bookworm` hits
|
|
# exactly the restriction terdut-server's ci.yaml already documents for
|
|
# get.helm.sh/github.com -- TLS handshake timeout reaching github.com from the dind
|
|
# bridge. No `container:` here, unlike every other Go job in this org's repos, on
|
|
# the same theory as terdut-server's `chart` job (which reaches get.helm.sh only by
|
|
# running on the host, not in a container) -- this is that same fix applied to a Go
|
|
# job for the first time, so it additionally assumes the runner host has Go
|
|
# available directly, which no prior workflow here has needed. If this goes red on
|
|
# "go: command not found" rather than the envtest fetch, that assumption was wrong
|
|
# and this needs the other fix instead (allowlist github.com's release CDN on the
|
|
# runner's NetworkPolicy, in Ryuvia/charts or Ryuvia/k8s).
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
env:
|
|
REF_NAME: ${{ github.ref_name }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: |
|
|
if [ -n "$HEAD_SHA" ]; then
|
|
# A pull_request ref_name is "<n>/merge", which is not a fetchable branch.
|
|
git clone "$REPO_URL" .
|
|
git checkout -q "$HEAD_SHA"
|
|
else
|
|
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
|
fi
|
|
|
|
- name: Format, lint and test
|
|
run: make fmt lint test
|
|
|
|
# No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No
|
|
# `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one
|
|
# alongside `test` once there's controller code worth scanning.
|