Stage 5: installer chart + release infra, kind e2e pass through the chart
Release / test (push) Successful in 2m48s
CI / chart (push) Successful in 1s
CI / security (push) Successful in 1m3s
CI / test (push) Successful in 2m5s
Release / chart (push) Successful in 4s
Release / image (push) Successful in 7m6s
Release / scan-image (push) Failing after 33s

Chart (charts/terdut-operator) generated via kubebuilder's own helm/v2-alpha
plugin from config/'s kustomize output -- CRDs + manager Deployment/RBAC
come from the same markers every other stage already generates, one source
of truth. Hand-added on top: the optional terdutServer values block
(DESIGN.md §10's "helm install and get a server" path, off by default) and
the release-skill plumbing -- .release.conf, release-vars/helm-lint/push/
helm-package/helm-push/release Makefile targets, .gitea/workflows/release.yaml
(test -> image/chart -> scan-image) -- mirroring terdut-server's own shape
(registry/namespace convention, multi-arch buildx push, trivy/govulncheck/
gitleaks scans). ci.yaml gains security and chart jobs to match.

Two real issues caught while wiring this, fixed before either shipped:
- Dockerfile's builder stage didn't pin --platform=$BUILDPLATFORM, which
  would have made a multi-arch release build fail outright on this org's
  runners (no binfmt registration) -- same fix terdut-server's own
  Dockerfile already needed for the same reason.
- govulncheck found one real, reachable finding: google.golang.org/grpc
  v1.82.1 (transitive via controller-runtime's otel exporter), fixed by
  bumping to v1.83.1.

Full golden-path kind e2e pass, this time through `helm install` rather than
raw kustomize: TerdutServer (real terdut-server v0.33.0 image) -> TerdutTeam
-> one of each child kind, each confirmed Ready and then independently
confirmed against terdut-server's own API from inside the cluster (not just
the operator's own status). Deleted every CR in reverse order and confirmed
server-side cleanup the same independent way for all three child kinds, the
team, and the server. No new bugs found -- Stage 1's own kind pass already
caught what a real cluster catches that envtest can't.

Also dropped the kubebuilder helm plugin's default .github/workflows/
scaffold, same as Stage 0 already did for the main scaffold: this org runs
on Gitea, not GitHub.

Not done here, deliberately: an actual tagged release. release-preflight
found no terdut-operator/ entry under Ryuvia/charts yet to bump -- that
one-time wrapper bootstrap is a decision about deploying this operator for
real, not a side effect of finishing this stage.

make fmt lint test helm-lint build all clean.
This commit is contained in:
Niklas Ye
2026-10-01 14:47:10 +02:00
parent 048f4448c4
commit b4ccdb09d5
50 changed files with 3190 additions and 22 deletions
+187
View File
@@ -259,3 +259,190 @@ endef
define gomodver
$(shell go list -m -f '{{if .Replace}}{{.Replace.Version}}{{else}}{{.Version}}{{end}}' $(1) 2>/dev/null)
endef
##@ Helm Deployment
## Helm binary to use for deploying the chart
HELM ?= helm
## Namespace to deploy the Helm release
HELM_NAMESPACE ?= terdut-operator-system
## Name of the Helm release
HELM_RELEASE ?= terdut-operator
## Path to the Helm chart directory. Must stay equal to HELM_CHART below
## (the release process's own name for this same path) -- two variables
## because this one is kubebuilder's own scaffold and that one is the
## release skill's contract, not because the path differs.
HELM_CHART_DIR ?= charts/terdut-operator
## Additional arguments to pass to helm commands
HELM_EXTRA_ARGS ?=
.PHONY: install-helm
install-helm: ## Install the latest version of Helm.
@command -v $(HELM) >/dev/null 2>&1 || { \
echo "Installing Helm..." && \
curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4 | bash; \
}
.PHONY: helm-deploy
helm-deploy: install-helm ## Deploy manager to the K8s cluster via Helm. Specify an image with IMG.
IMG="$(IMG)"; $(HELM) upgrade --install $(HELM_RELEASE) $(HELM_CHART_DIR) \
--namespace $(HELM_NAMESPACE) \
--create-namespace \
--set manager.image.repository=$${IMG%:*} \
--set manager.image.tag=$${IMG##*:} \
--wait \
--timeout 5m \
$(HELM_EXTRA_ARGS)
.PHONY: helm-uninstall
helm-uninstall: ## Uninstall the Helm release from the K8s cluster.
$(HELM) uninstall $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
.PHONY: helm-status
helm-status: ## Show Helm release status.
$(HELM) status $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
.PHONY: helm-history
helm-history: ## Show Helm release history.
$(HELM) history $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
.PHONY: helm-rollback
helm-rollback: ## Rollback to previous Helm release.
$(HELM) rollback $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
##@ Release
# Everything below is read by the `release` skill (~/.claude/skills/release), not by
# anything above it in this file -- mirrors terdut-server's Makefile section for
# section, adapted for this repo (no Postgres service for tests, no CLI binaries to
# cross-compile, one image + one chart to publish).
REGISTRY := git.ryuvia.com
# The personal namespace, not ryuvia -- same reasoning as terdut-server: Gitea scopes
# package visibility to the owner with no per-package override, so publishing here
# keeps the image and chart anonymously pullable and Flux needs no registry
# credentials to pull them.
OWNER := niklas
IMAGE := $(REGISTRY)/$(OWNER)/terdut-operator
HELM_CHART := charts/terdut-operator
HELM_REPO := oci://$(REGISTRY)/$(OWNER)
.PHONY: release-vars
release-vars: ## Print the variables the release process reads
@printf 'IMAGE=%s\nHELM_CHART=%s\nHELM_REPO=%s\n' '$(IMAGE)' '$(HELM_CHART)' '$(HELM_REPO)'
# database is required (dsn xor postgresClusterRef, DatabaseSpec's own CEL rule) once
# terdutServer.enabled, so the chart's own `required` calls fail a bare
# `--set terdutServer.enabled=true` the same way a real install without a database
# would be rejected at apply time -- this set gives that path something valid to
# render against, the way terdut-server's own HELM_LINT_SET supplies its one
# required field (database.dsn) for the same reason.
HELM_LINT_SET = --set terdutServer.enabled=true \
--set terdutServer.image.tag=v0.0.0 \
--set terdutServer.networking.hostname=terdut.example.invalid \
--set 'terdutServer.database.dsn=postgres://terdut@terdut-postgres:5432/terdut?sslmode=require'
.PHONY: helm-lint
helm-lint: ## Lint and render the chart
helm lint $(HELM_CHART)
helm template terdut-operator $(HELM_CHART) --namespace terdut-operator-system >/dev/null
# Second pass: the optional TerdutServer CR template (off by default, so the
# bare render above never exercises it at all).
helm lint $(HELM_CHART) $(HELM_LINT_SET)
helm template terdut-operator $(HELM_CHART) --namespace terdut-operator-system \
$(HELM_LINT_SET) >/dev/null
## --- publishing ---
#
# Exist so .gitea/workflows/release.yaml can call `make push` / `make helm-package
# helm-push` instead of restating the build in YAML -- one definition, runnable
# locally, reviewable in a diff. Publishing happens by pushing a tag; nothing else.
#
# VERSION is the git tag, passed in by the workflow. require-version is why a stray
# local `make push` cannot publish: dev is not a version anyone releases.
VERSION ?= dev
# Helm requires strict SemVer -- strip a leading 'v' if present.
CHART_VERSION := $(shell echo "$(VERSION)" | sed 's/^v//')
# Named RELEASE_PLATFORMS, not PLATFORMS: that name is already taken above by
# kubebuilder's own docker-buildx target (a 4-platform list this repo's own release
# process doesn't use), and `?=` on an already-set variable is a silent no-op, not an
# override -- reusing it here would have quietly built s390x/ppc64le instead of the
# two platforms this target actually intends.
RELEASE_PLATFORMS ?= linux/amd64,linux/arm64
BUILDX_BUILDER ?= terdut-operator-release
# An isolated repo list, same reasoning as terdut-server's: the machine-wide one is
# not this build's business, and one unreachable entry in it aborts otherwise-fine
# helm commands. HELM_REPOSITORY_CACHE is deliberately NOT overridden alongside it --
# helm writes a refreshed index to the default cache and then looks for it there.
HELM_ISOLATED = HELM_REPOSITORY_CONFIG=$(CURDIR)/.helm-repos.yaml
.PHONY: require-version
require-version:
@test "$(VERSION)" != "dev" || \
(echo "VERSION=dev names no release -- pass VERSION=vX.Y.Z (the workflow passes the tag)" && exit 1)
# Multi-arch, so this is build-and-push in one step, same reasoning as
# terdut-server's own `push`: buildx cannot load a multi-platform result into the
# local image store, so there is no separate local-only `build` target here either.
#
# No QEMU: the Dockerfile's builder stage runs on $$BUILDPLATFORM and cross-compiles
# via GOOS/GOARCH, so both platforms build natively -- same fix as terdut-server's
# Dockerfile, for the same reason (this CI runner has no binfmt registration).
.PHONY: push
push: require-version ## Build and publish the multi-arch image
docker buildx create --name $(BUILDX_BUILDER) --use 2>/dev/null || docker buildx use $(BUILDX_BUILDER)
docker buildx build \
--platform $(RELEASE_PLATFORMS) \
--tag "$(IMAGE):latest" \
--tag "$(IMAGE):$(VERSION)" \
--push .
# --version/--app-version come from the tag, so Chart.yaml's own fields decide
# nothing about what gets published -- same as terdut-server's chart.
.PHONY: helm-package
helm-package: require-version ## Package the chart, versioned from the tag
$(HELM_ISOLATED) helm package $(HELM_CHART) \
--version $(CHART_VERSION) \
--app-version $(VERSION) \
--destination dist
.PHONY: helm-push
helm-push: require-version ## Push the packaged chart to the OCI registry
$(HELM_ISOLATED) helm push dist/terdut-operator-$(CHART_VERSION).tgz $(HELM_REPO)
.PHONY: release
release: push helm-package helm-push ## Publish image + chart (the workflow's one call)
## --- security ---
GOVULNCHECK_VERSION := v1.1.4
GITLEAKS_VERSION := v8.30.0
TRIVY_VERSION := 0.73.0
# Symbol-level, not dependency-level, same as terdut-server: govulncheck reports a
# vulnerability only when the code can actually reach it.
.PHONY: security-go
security-go: ## Scan Go deps for known CVEs (govulncheck)
go run golang.org/x/vuln/cmd/govulncheck@$(GOVULNCHECK_VERSION) ./...
# --no-git scans the working tree rather than the history, so this catches a secret
# on the way in; it says nothing about what is already committed.
.PHONY: security-secrets
security-secrets: ## Scan the working tree for committed secrets (gitleaks)
go run github.com/zricethezav/gitleaks/v8@$(GITLEAKS_VERSION) detect --no-git \
--source . --redact --no-banner --exit-code 1
# Scans the pushed image, not a local one -- trivy cannot read a locally built image
# on this runner, same reasoning as terdut-server. A red scan means: do not bump the
# wrapper chart in Ryuvia/charts to this version; it does not unpublish anything.
.PHONY: security-image
security-image: require-version ## Scan the pushed image for CVEs (needs VERSION)
docker run --rm -e TRIVY_USERNAME -e TRIVY_PASSWORD \
-v trivy-cache:/root/.cache/trivy \
docker.io/aquasec/trivy:$(TRIVY_VERSION) image --severity HIGH,CRITICAL \
--ignore-unfixed --exit-code 1 $(IMAGE):$(VERSION)