0e89816ad4
CI / test (push) Successful in 7m59s
Clean result, isolated from lint's own unrelated github.com flakiness: post-MTU-fix (Ryuvia/charts#272), `make test` alone hits the exact same "TLS handshake timeout" fetching envtest-v1.37.0-linux-amd64.tar.gz as before the fix. Byte-for-byte identical error. The dind sidecar's MTU mismatch was real (measured 1450 vs 1500 per the other session's report) but it was not (solely) the cause of this specific failure. Separately and incidentally: golangci-lint's own custom-gcl build also does a plain `git clone https://github.com/...` and that is now failing too (2/2, ~2.5min hang then generic exit 128) where it briefly succeeded in an earlier pre-fix run -- noted in the comment but not chased further here; worth someone's attention if it keeps recurring, since it'll block `lint` regardless of the envtest question.
90 lines
4.2 KiB
YAML
90 lines
4.2 KiB
YAML
name: CI
|
|
|
|
# Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is
|
|
# late, so this runs the same checks on the way in instead.
|
|
#
|
|
# push is scoped to main rather than all branches so a branch pushed as part of a pull
|
|
# request is not checked twice.
|
|
#
|
|
# No actions/checkout, deliberately -- same reason as terdut-server: the runner image's
|
|
# `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4
|
|
# dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git
|
|
# directly avoids JS actions entirely. This repo is public, so the clone needs no
|
|
# credential.
|
|
#
|
|
# `${{ }}` values are passed through `env:` and referenced as quoted shell variables --
|
|
# a ref name is attacker-influenced by anyone who can push a branch or open a PR.
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
concurrency:
|
|
group: ci-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git
|
|
|
|
jobs:
|
|
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
|
|
# and a green working copy mean the same thing by construction. `test` also drives
|
|
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
|
|
# chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases
|
|
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s
|
|
# now for every version tried, confirmed 2026-09-30, no fallback there).
|
|
#
|
|
# This currently fails in CI: TLS handshake timeout reaching github.com from inside
|
|
# this container, same symptom terdut-server's ci.yaml already documents for
|
|
# get.helm.sh/github.com. Two things ruled out already, so this isn't "add an
|
|
# allowlist entry":
|
|
# - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only
|
|
# NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design
|
|
# ("egress is deliberately untouched... CI pulls from registries and package
|
|
# indexes that are not enumerable here" -- see its own comment, issue #128).
|
|
# There is no in-repo egress rule to edit for this.
|
|
# - Running this job on the bare runner host instead of in a container (tried and
|
|
# reverted, same as terdut-server's `chart` job does for get.helm.sh) fails
|
|
# earlier and differently: "go: command not found" -- the host has no Go.
|
|
# - The act-runner dind sidecar's MTU (Ryuvia/charts#272, merged and reconciled
|
|
# 2026-09-30: explicit `"mtu": 1450` in its daemon.json, matching Flannel's
|
|
# VXLAN-reduced pod MTU, since dockerd's bridge networks default to 1500
|
|
# unset) -- tested against this exact failure post-fix (isolated `make test`,
|
|
# bypassing lint's own unrelated github.com flakiness) and got the identical
|
|
# "TLS handshake timeout" fetching envtest-v1.37.0-linux-amd64.tar.gz. Ruled
|
|
# out: the MTU mismatch was real but wasn't (solely) the cause of this.
|
|
# So whatever blocks github.com from the dind bridge sits outside anything this
|
|
# workspace's repos configure, and outside the MTU theory -- still unidentified as
|
|
# of 2026-09-30. `make test` fails on the envtest fetch until that's found and
|
|
# fixed (or the binaries are vendored -- see ROADMAP.md/the PR discussion for why
|
|
# that was declined for now).
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: golang:1.26.6-bookworm
|
|
volumes:
|
|
- go-mod-cache:/go/pkg/mod
|
|
- go-build-cache:/root/.cache/go-build
|
|
- gobin-cache:/go/bin
|
|
|
|
steps:
|
|
- name: Checkout
|
|
env:
|
|
REF_NAME: ${{ github.ref_name }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: |
|
|
if [ -n "$HEAD_SHA" ]; then
|
|
# A pull_request ref_name is "<n>/merge", which is not a fetchable branch.
|
|
git clone "$REPO_URL" .
|
|
git checkout -q "$HEAD_SHA"
|
|
else
|
|
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
|
fi
|
|
|
|
- name: Format, lint and test
|
|
run: make fmt lint test
|
|
|
|
# No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No
|
|
# `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one
|
|
# alongside `test` once there's controller code worth scanning.
|