Add CI, repo CLAUDE.md, and finish Stage 0
- .gitea/workflows/ci.yaml: fmt/lint/test, same no-actions/checkout-and-manual-clone
shape as terdut-server's ci.yaml, and the same reasoning for why (Node/ES2022
incompatibility on the runner image). No chart/security jobs yet -- nothing for
either to check until Stage 6 / real controller code exists.
- CLAUDE.md: Checks + Release sections, matching the sibling repos' convention from
the workspace-level CLAUDE.md ("each repo has its own CLAUDE.md... read it before
working in that repo"). Release is explicitly marked not-wired-yet rather than
copying terdut-server's, since there's no chart to release against until Stage 6.
- ROADMAP.md: moved the .release.conf bullet out of Stage 0 (it names a HELM_CHART
this repo doesn't have yet) -- it was already duplicated into Stage 6, which is
where it actually belongs.
Stage 0 done: `make fmt lint test` verified green locally. Real open question the CI
workflow's comments flag rather than assume past: whether storage.googleapis.com
(envtest's binary source) is reachable from this Gitea runner's container network the
way proxy.golang.org is -- terdut-server's own ci.yaml notes get.helm.sh/github.com are
not. Only running the workflow for real will confirm; the comment names the fallback
(move the job out of `container:`, like terdut-server's chart job) if it isn't.
This commit is contained in:
@@ -0,0 +1,68 @@
|
||||
name: CI
|
||||
|
||||
# Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is
|
||||
# late, so this runs the same checks on the way in instead.
|
||||
#
|
||||
# push is scoped to main rather than all branches so a branch pushed as part of a pull
|
||||
# request is not checked twice.
|
||||
#
|
||||
# No actions/checkout, deliberately -- same reason as terdut-server: the runner image's
|
||||
# `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4
|
||||
# dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git
|
||||
# directly avoids JS actions entirely. This repo is public, so the clone needs no
|
||||
# credential.
|
||||
#
|
||||
# `${{ }}` values are passed through `env:` and referenced as quoted shell variables --
|
||||
# a ref name is attacker-influenced by anyone who can push a branch or open a PR.
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
env:
|
||||
REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git
|
||||
|
||||
jobs:
|
||||
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
|
||||
# and a green working copy mean the same thing by construction. `test` also drives
|
||||
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
|
||||
# chain), which needs storage.googleapis.com to fetch the envtest kube-apiserver/etcd
|
||||
# binaries -- unconfirmed whether that host is reachable from this runner's dind
|
||||
# bridge the way proxy.golang.org and git.ryuvia.com are (terdut-server's ci.yaml
|
||||
# flags get.helm.sh and github.com as *not* reachable from here); if this job goes
|
||||
# red on the fetch specifically rather than on a real test failure, move it out of
|
||||
# `container:` the way the chart job in terdut-server's ci.yaml runs on the host
|
||||
# instead, for the same "can't reach a fetch target from the dind bridge" reason.
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: golang:1.26.6-bookworm
|
||||
volumes:
|
||||
- go-mod-cache:/go/pkg/mod
|
||||
- go-build-cache:/root/.cache/go-build
|
||||
- gobin-cache:/go/bin
|
||||
|
||||
steps:
|
||||
- name: Checkout
|
||||
env:
|
||||
REF_NAME: ${{ github.ref_name }}
|
||||
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
||||
run: |
|
||||
if [ -n "$HEAD_SHA" ]; then
|
||||
# A pull_request ref_name is "<n>/merge", which is not a fetchable branch.
|
||||
git clone "$REPO_URL" .
|
||||
git checkout -q "$HEAD_SHA"
|
||||
else
|
||||
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
||||
fi
|
||||
|
||||
- name: Format, lint and test
|
||||
run: make fmt lint test
|
||||
|
||||
# No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No
|
||||
# `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one
|
||||
# alongside `test` once there's controller code worth scanning.
|
||||
Reference in New Issue
Block a user