Files
terdut-operator/.gitea/workflows/ci.yaml
T
Niklas Ye dd955bbf1a
CI / test (push) Successful in 1m17s
CI: update comment -- second MTU fix resolves the github.com timeout
Confirmed via the actual job log (run 857, job 1931), not just the exit
code: setup-envtest fetches envtest-v1.37.0-linux-amd64.tar.gz from
github.com in ~4s now, where it previously TLS-handshake-timed-out every
time. golangci-lint's own git-clone-to-github.com (the confound from the
first fix attempt) also went through fine in the same run.

Stage 0 is now fully green end to end: fmt, lint, test (envtest included).
2026-09-30 21:41:29 +02:00

84 lines
3.7 KiB
YAML

name: CI
# Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is
# late, so this runs the same checks on the way in instead.
#
# push is scoped to main rather than all branches so a branch pushed as part of a pull
# request is not checked twice.
#
# No actions/checkout, deliberately -- same reason as terdut-server: the runner image's
# `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4
# dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git
# directly avoids JS actions entirely. This repo is public, so the clone needs no
# credential.
#
# `${{ }}` values are passed through `env:` and referenced as quoted shell variables --
# a ref name is attacker-influenced by anyone who can push a branch or open a PR.
on:
push:
branches: [main]
pull_request:
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
env:
REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git
jobs:
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
# and a green working copy mean the same thing by construction. `test` also drives
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
# chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s
# now for every version tried, confirmed 2026-09-30, no fallback there).
#
# This used to fail in CI: TLS handshake timeout reaching github.com from inside
# this container (same symptom terdut-server's ci.yaml documents for
# get.helm.sh/github.com), fetching the envtest kube-apiserver/etcd binaries from
# GitHub Releases (setup-envtest v0.25's only source -- the legacy GCS
# kubebuilder-tools bucket 403s now for every version tried, no fallback there).
# History, in case it recurs:
# - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only
# NetworkPolicy in the cluster and is deny-ingress only -- ruled out, no
# in-repo egress rule governs this.
# - Running this job on the bare runner host instead of in a container fails
# earlier and differently ("go: command not found", no Go there) -- ruled out.
# - The act-runner dind sidecar's MTU mismatch (1450 pod vs. 1500 Docker-bridge
# default) was real but an initial fix for it (Ryuvia/charts#272) did not
# resolve this specific failure when tested in isolation -- see Ryuvia/charts#271
# for that round's write-up.
# - A second attempt at the MTU fix, 2026-09-30, did resolve it: `setup-envtest`
# now fetches envtest-v1.37.0-linux-amd64.tar.gz from github.com in ~4s and
# `test` passes. Confirmed via the actual job log, not just the exit code.
test:
runs-on: ubuntu-latest
container:
image: golang:1.26.6-bookworm
volumes:
- go-mod-cache:/go/pkg/mod
- go-build-cache:/root/.cache/go-build
- gobin-cache:/go/bin
steps:
- name: Checkout
env:
REF_NAME: ${{ github.ref_name }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
if [ -n "$HEAD_SHA" ]; then
# A pull_request ref_name is "<n>/merge", which is not a fetchable branch.
git clone "$REPO_URL" .
git checkout -q "$HEAD_SHA"
else
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
fi
- name: Format, lint and test
run: make fmt lint test
# No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No
# `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one
# alongside `test` once there's controller code worth scanning.