name: CI # Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is # late, so this runs the same checks on the way in instead. # # push is scoped to main rather than all branches so a branch pushed as part of a pull # request is not checked twice. # # No actions/checkout, deliberately -- same reason as terdut-server: the runner image's # `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4 # dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git # directly avoids JS actions entirely. This repo is public, so the clone needs no # credential. # # `${{ }}` values are passed through `env:` and referenced as quoted shell variables -- # a ref name is attacker-influenced by anyone who can push a branch or open a PR. on: push: branches: [main] pull_request: concurrency: group: ci-${{ github.ref }} cancel-in-progress: true env: REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git jobs: # `make fmt lint test` is exactly what a developer runs locally, so a green job here # and a green working copy mean the same thing by construction. `test` also drives # controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test` # chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases # (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s # now for every version tried, confirmed 2026-09-30, no fallback there). # # This currently fails in CI: TLS handshake timeout reaching github.com from inside # this container, same symptom terdut-server's ci.yaml already documents for # get.helm.sh/github.com. Two things ruled out already, so this isn't "add an # allowlist entry": # - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only # NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design # ("egress is deliberately untouched... CI pulls from registries and package # indexes that are not enumerable here" -- see its own comment, issue #128). # There is no in-repo egress rule to edit for this. # - Running this job on the bare runner host instead of in a container (tried and # reverted, same as terdut-server's `chart` job does for get.helm.sh) fails # earlier and differently: "go: command not found" -- the host has no Go. # So whatever blocks github.com from the dind bridge sits outside anything this # workspace's repos configure -- a firewall/DNS layer neither Ryuvia/charts nor # Ryuvia/k8s expresses in Kubernetes objects. `make test` fails on the envtest fetch # until that's found and fixed (or the binaries are vendored -- see ROADMAP.md/the # PR discussion for why that was declined for now). test: runs-on: ubuntu-latest container: image: golang:1.26.6-bookworm volumes: - go-mod-cache:/go/pkg/mod - go-build-cache:/root/.cache/go-build - gobin-cache:/go/bin steps: - name: Checkout env: REF_NAME: ${{ github.ref_name }} HEAD_SHA: ${{ github.event.pull_request.head.sha }} run: | if [ -n "$HEAD_SHA" ]; then # A pull_request ref_name is "/merge", which is not a fetchable branch. git clone "$REPO_URL" . git checkout -q "$HEAD_SHA" else git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" . fi - name: Format, lint and test run: make fmt lint test # No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No # `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one # alongside `test` once there's controller code worth scanning.