Stage 5: installer chart + release infra, kind e2e pass through the chart
Release / test (push) Successful in 2m48s
CI / chart (push) Successful in 1s
CI / security (push) Successful in 1m3s
CI / test (push) Successful in 2m5s
Release / chart (push) Successful in 4s
Release / image (push) Successful in 7m6s
Release / scan-image (push) Failing after 33s
Release / test (push) Successful in 2m48s
CI / chart (push) Successful in 1s
CI / security (push) Successful in 1m3s
CI / test (push) Successful in 2m5s
Release / chart (push) Successful in 4s
Release / image (push) Successful in 7m6s
Release / scan-image (push) Failing after 33s
Chart (charts/terdut-operator) generated via kubebuilder's own helm/v2-alpha plugin from config/'s kustomize output -- CRDs + manager Deployment/RBAC come from the same markers every other stage already generates, one source of truth. Hand-added on top: the optional terdutServer values block (DESIGN.md §10's "helm install and get a server" path, off by default) and the release-skill plumbing -- .release.conf, release-vars/helm-lint/push/ helm-package/helm-push/release Makefile targets, .gitea/workflows/release.yaml (test -> image/chart -> scan-image) -- mirroring terdut-server's own shape (registry/namespace convention, multi-arch buildx push, trivy/govulncheck/ gitleaks scans). ci.yaml gains security and chart jobs to match. Two real issues caught while wiring this, fixed before either shipped: - Dockerfile's builder stage didn't pin --platform=$BUILDPLATFORM, which would have made a multi-arch release build fail outright on this org's runners (no binfmt registration) -- same fix terdut-server's own Dockerfile already needed for the same reason. - govulncheck found one real, reachable finding: google.golang.org/grpc v1.82.1 (transitive via controller-runtime's otel exporter), fixed by bumping to v1.83.1. Full golden-path kind e2e pass, this time through `helm install` rather than raw kustomize: TerdutServer (real terdut-server v0.33.0 image) -> TerdutTeam -> one of each child kind, each confirmed Ready and then independently confirmed against terdut-server's own API from inside the cluster (not just the operator's own status). Deleted every CR in reverse order and confirmed server-side cleanup the same independent way for all three child kinds, the team, and the server. No new bugs found -- Stage 1's own kind pass already caught what a real cluster catches that envtest can't. Also dropped the kubebuilder helm plugin's default .github/workflows/ scaffold, same as Stage 0 already did for the main scaffold: this org runs on Gitea, not GitHub. Not done here, deliberately: an actual tagged release. release-preflight found no terdut-operator/ entry under Ryuvia/charts yet to bump -- that one-time wrapper bootstrap is a decision about deploying this operator for real, not a side effect of finishing this stage. make fmt lint test helm-lint build all clean.
This commit is contained in:
@@ -259,3 +259,190 @@ endef
|
||||
define gomodver
|
||||
$(shell go list -m -f '{{if .Replace}}{{.Replace.Version}}{{else}}{{.Version}}{{end}}' $(1) 2>/dev/null)
|
||||
endef
|
||||
|
||||
##@ Helm Deployment
|
||||
|
||||
## Helm binary to use for deploying the chart
|
||||
HELM ?= helm
|
||||
## Namespace to deploy the Helm release
|
||||
HELM_NAMESPACE ?= terdut-operator-system
|
||||
## Name of the Helm release
|
||||
HELM_RELEASE ?= terdut-operator
|
||||
## Path to the Helm chart directory. Must stay equal to HELM_CHART below
|
||||
## (the release process's own name for this same path) -- two variables
|
||||
## because this one is kubebuilder's own scaffold and that one is the
|
||||
## release skill's contract, not because the path differs.
|
||||
HELM_CHART_DIR ?= charts/terdut-operator
|
||||
## Additional arguments to pass to helm commands
|
||||
HELM_EXTRA_ARGS ?=
|
||||
|
||||
.PHONY: install-helm
|
||||
install-helm: ## Install the latest version of Helm.
|
||||
@command -v $(HELM) >/dev/null 2>&1 || { \
|
||||
echo "Installing Helm..." && \
|
||||
curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4 | bash; \
|
||||
}
|
||||
|
||||
.PHONY: helm-deploy
|
||||
helm-deploy: install-helm ## Deploy manager to the K8s cluster via Helm. Specify an image with IMG.
|
||||
IMG="$(IMG)"; $(HELM) upgrade --install $(HELM_RELEASE) $(HELM_CHART_DIR) \
|
||||
--namespace $(HELM_NAMESPACE) \
|
||||
--create-namespace \
|
||||
--set manager.image.repository=$${IMG%:*} \
|
||||
--set manager.image.tag=$${IMG##*:} \
|
||||
--wait \
|
||||
--timeout 5m \
|
||||
$(HELM_EXTRA_ARGS)
|
||||
|
||||
.PHONY: helm-uninstall
|
||||
helm-uninstall: ## Uninstall the Helm release from the K8s cluster.
|
||||
$(HELM) uninstall $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
||||
|
||||
.PHONY: helm-status
|
||||
helm-status: ## Show Helm release status.
|
||||
$(HELM) status $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
||||
|
||||
.PHONY: helm-history
|
||||
helm-history: ## Show Helm release history.
|
||||
$(HELM) history $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
||||
|
||||
.PHONY: helm-rollback
|
||||
helm-rollback: ## Rollback to previous Helm release.
|
||||
$(HELM) rollback $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
||||
|
||||
##@ Release
|
||||
|
||||
# Everything below is read by the `release` skill (~/.claude/skills/release), not by
|
||||
# anything above it in this file -- mirrors terdut-server's Makefile section for
|
||||
# section, adapted for this repo (no Postgres service for tests, no CLI binaries to
|
||||
# cross-compile, one image + one chart to publish).
|
||||
|
||||
REGISTRY := git.ryuvia.com
|
||||
# The personal namespace, not ryuvia -- same reasoning as terdut-server: Gitea scopes
|
||||
# package visibility to the owner with no per-package override, so publishing here
|
||||
# keeps the image and chart anonymously pullable and Flux needs no registry
|
||||
# credentials to pull them.
|
||||
OWNER := niklas
|
||||
|
||||
IMAGE := $(REGISTRY)/$(OWNER)/terdut-operator
|
||||
HELM_CHART := charts/terdut-operator
|
||||
HELM_REPO := oci://$(REGISTRY)/$(OWNER)
|
||||
|
||||
.PHONY: release-vars
|
||||
release-vars: ## Print the variables the release process reads
|
||||
@printf 'IMAGE=%s\nHELM_CHART=%s\nHELM_REPO=%s\n' '$(IMAGE)' '$(HELM_CHART)' '$(HELM_REPO)'
|
||||
|
||||
# database is required (dsn xor postgresClusterRef, DatabaseSpec's own CEL rule) once
|
||||
# terdutServer.enabled, so the chart's own `required` calls fail a bare
|
||||
# `--set terdutServer.enabled=true` the same way a real install without a database
|
||||
# would be rejected at apply time -- this set gives that path something valid to
|
||||
# render against, the way terdut-server's own HELM_LINT_SET supplies its one
|
||||
# required field (database.dsn) for the same reason.
|
||||
HELM_LINT_SET = --set terdutServer.enabled=true \
|
||||
--set terdutServer.image.tag=v0.0.0 \
|
||||
--set terdutServer.networking.hostname=terdut.example.invalid \
|
||||
--set 'terdutServer.database.dsn=postgres://terdut@terdut-postgres:5432/terdut?sslmode=require'
|
||||
|
||||
.PHONY: helm-lint
|
||||
helm-lint: ## Lint and render the chart
|
||||
helm lint $(HELM_CHART)
|
||||
helm template terdut-operator $(HELM_CHART) --namespace terdut-operator-system >/dev/null
|
||||
# Second pass: the optional TerdutServer CR template (off by default, so the
|
||||
# bare render above never exercises it at all).
|
||||
helm lint $(HELM_CHART) $(HELM_LINT_SET)
|
||||
helm template terdut-operator $(HELM_CHART) --namespace terdut-operator-system \
|
||||
$(HELM_LINT_SET) >/dev/null
|
||||
|
||||
## --- publishing ---
|
||||
#
|
||||
# Exist so .gitea/workflows/release.yaml can call `make push` / `make helm-package
|
||||
# helm-push` instead of restating the build in YAML -- one definition, runnable
|
||||
# locally, reviewable in a diff. Publishing happens by pushing a tag; nothing else.
|
||||
#
|
||||
# VERSION is the git tag, passed in by the workflow. require-version is why a stray
|
||||
# local `make push` cannot publish: dev is not a version anyone releases.
|
||||
|
||||
VERSION ?= dev
|
||||
|
||||
# Helm requires strict SemVer -- strip a leading 'v' if present.
|
||||
CHART_VERSION := $(shell echo "$(VERSION)" | sed 's/^v//')
|
||||
|
||||
# Named RELEASE_PLATFORMS, not PLATFORMS: that name is already taken above by
|
||||
# kubebuilder's own docker-buildx target (a 4-platform list this repo's own release
|
||||
# process doesn't use), and `?=` on an already-set variable is a silent no-op, not an
|
||||
# override -- reusing it here would have quietly built s390x/ppc64le instead of the
|
||||
# two platforms this target actually intends.
|
||||
RELEASE_PLATFORMS ?= linux/amd64,linux/arm64
|
||||
BUILDX_BUILDER ?= terdut-operator-release
|
||||
|
||||
# An isolated repo list, same reasoning as terdut-server's: the machine-wide one is
|
||||
# not this build's business, and one unreachable entry in it aborts otherwise-fine
|
||||
# helm commands. HELM_REPOSITORY_CACHE is deliberately NOT overridden alongside it --
|
||||
# helm writes a refreshed index to the default cache and then looks for it there.
|
||||
HELM_ISOLATED = HELM_REPOSITORY_CONFIG=$(CURDIR)/.helm-repos.yaml
|
||||
|
||||
.PHONY: require-version
|
||||
require-version:
|
||||
@test "$(VERSION)" != "dev" || \
|
||||
(echo "VERSION=dev names no release -- pass VERSION=vX.Y.Z (the workflow passes the tag)" && exit 1)
|
||||
|
||||
# Multi-arch, so this is build-and-push in one step, same reasoning as
|
||||
# terdut-server's own `push`: buildx cannot load a multi-platform result into the
|
||||
# local image store, so there is no separate local-only `build` target here either.
|
||||
#
|
||||
# No QEMU: the Dockerfile's builder stage runs on $$BUILDPLATFORM and cross-compiles
|
||||
# via GOOS/GOARCH, so both platforms build natively -- same fix as terdut-server's
|
||||
# Dockerfile, for the same reason (this CI runner has no binfmt registration).
|
||||
.PHONY: push
|
||||
push: require-version ## Build and publish the multi-arch image
|
||||
docker buildx create --name $(BUILDX_BUILDER) --use 2>/dev/null || docker buildx use $(BUILDX_BUILDER)
|
||||
docker buildx build \
|
||||
--platform $(RELEASE_PLATFORMS) \
|
||||
--tag "$(IMAGE):latest" \
|
||||
--tag "$(IMAGE):$(VERSION)" \
|
||||
--push .
|
||||
|
||||
# --version/--app-version come from the tag, so Chart.yaml's own fields decide
|
||||
# nothing about what gets published -- same as terdut-server's chart.
|
||||
.PHONY: helm-package
|
||||
helm-package: require-version ## Package the chart, versioned from the tag
|
||||
$(HELM_ISOLATED) helm package $(HELM_CHART) \
|
||||
--version $(CHART_VERSION) \
|
||||
--app-version $(VERSION) \
|
||||
--destination dist
|
||||
|
||||
.PHONY: helm-push
|
||||
helm-push: require-version ## Push the packaged chart to the OCI registry
|
||||
$(HELM_ISOLATED) helm push dist/terdut-operator-$(CHART_VERSION).tgz $(HELM_REPO)
|
||||
|
||||
.PHONY: release
|
||||
release: push helm-package helm-push ## Publish image + chart (the workflow's one call)
|
||||
|
||||
## --- security ---
|
||||
|
||||
GOVULNCHECK_VERSION := v1.1.4
|
||||
GITLEAKS_VERSION := v8.30.0
|
||||
TRIVY_VERSION := 0.73.0
|
||||
|
||||
# Symbol-level, not dependency-level, same as terdut-server: govulncheck reports a
|
||||
# vulnerability only when the code can actually reach it.
|
||||
.PHONY: security-go
|
||||
security-go: ## Scan Go deps for known CVEs (govulncheck)
|
||||
go run golang.org/x/vuln/cmd/govulncheck@$(GOVULNCHECK_VERSION) ./...
|
||||
|
||||
# --no-git scans the working tree rather than the history, so this catches a secret
|
||||
# on the way in; it says nothing about what is already committed.
|
||||
.PHONY: security-secrets
|
||||
security-secrets: ## Scan the working tree for committed secrets (gitleaks)
|
||||
go run github.com/zricethezav/gitleaks/v8@$(GITLEAKS_VERSION) detect --no-git \
|
||||
--source . --redact --no-banner --exit-code 1
|
||||
|
||||
# Scans the pushed image, not a local one -- trivy cannot read a locally built image
|
||||
# on this runner, same reasoning as terdut-server. A red scan means: do not bump the
|
||||
# wrapper chart in Ryuvia/charts to this version; it does not unpublish anything.
|
||||
.PHONY: security-image
|
||||
security-image: require-version ## Scan the pushed image for CVEs (needs VERSION)
|
||||
docker run --rm -e TRIVY_USERNAME -e TRIVY_PASSWORD \
|
||||
-v trivy-cache:/root/.cache/trivy \
|
||||
docker.io/aquasec/trivy:$(TRIVY_VERSION) image --severity HIGH,CRITICAL \
|
||||
--ignore-unfixed --exit-code 1 $(IMAGE):$(VERSION)
|
||||
|
||||
Reference in New Issue
Block a user