a55489c7a9
CI / test (push) Failing after 3m23s
lint is currently blocked by an unrelated github.com git-clone failure (golangci-lint's custom-gcl build), which means the last two runs never reached setup-envtest -- the step the act-runner MTU fix (Ryuvia/charts#272) was meant to affect. Narrowing to `make test` alone to get a clean signal; will revert to `make fmt lint test` right after.
88 lines
4.1 KiB
YAML
88 lines
4.1 KiB
YAML
name: CI
|
|
|
|
# Same shape as terdut-server's ci.yaml: the release workflow gates a tag, which is
|
|
# late, so this runs the same checks on the way in instead.
|
|
#
|
|
# push is scoped to main rather than all branches so a branch pushed as part of a pull
|
|
# request is not checked twice.
|
|
#
|
|
# No actions/checkout, deliberately -- same reason as terdut-server: the runner image's
|
|
# `nodejs` package predates ES2022 static initialiser blocks, so actions/checkout@v4
|
|
# dies with `SyntaxError: Unexpected token '{'` before running. Cloning with git
|
|
# directly avoids JS actions entirely. This repo is public, so the clone needs no
|
|
# credential.
|
|
#
|
|
# `${{ }}` values are passed through `env:` and referenced as quoted shell variables --
|
|
# a ref name is attacker-influenced by anyone who can push a branch or open a PR.
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
concurrency:
|
|
group: ci-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
env:
|
|
REPO_URL: https://git.ryuvia.com/niklas/terdut-operator.git
|
|
|
|
jobs:
|
|
# `make fmt lint test` is exactly what a developer runs locally, so a green job here
|
|
# and a green working copy mean the same thing by construction. `test` also drives
|
|
# controller-gen/setup-envtest (via the Makefile's own `manifests generate ... test`
|
|
# chain), which fetches the envtest kube-apiserver/etcd binaries from GitHub Releases
|
|
# (setup-envtest v0.25's only source -- the legacy GCS kubebuilder-tools bucket 403s
|
|
# now for every version tried, confirmed 2026-09-30, no fallback there).
|
|
#
|
|
# This currently fails in CI: TLS handshake timeout reaching github.com from inside
|
|
# this container, same symptom terdut-server's ci.yaml already documents for
|
|
# get.helm.sh/github.com. Two things ruled out already, so this isn't "add an
|
|
# allowlist entry":
|
|
# - Ryuvia/charts' act-runner/templates/networkpolicy.yaml is the only
|
|
# NetworkPolicy in the cluster, and it is deny-ingress only, by explicit design
|
|
# ("egress is deliberately untouched... CI pulls from registries and package
|
|
# indexes that are not enumerable here" -- see its own comment, issue #128).
|
|
# There is no in-repo egress rule to edit for this.
|
|
# - Running this job on the bare runner host instead of in a container (tried and
|
|
# reverted, same as terdut-server's `chart` job does for get.helm.sh) fails
|
|
# earlier and differently: "go: command not found" -- the host has no Go.
|
|
# So whatever blocks github.com from the dind bridge sits outside anything this
|
|
# workspace's repos configure -- a firewall/DNS layer neither Ryuvia/charts nor
|
|
# Ryuvia/k8s expresses in Kubernetes objects. `make test` fails on the envtest fetch
|
|
# until that's found and fixed (or the binaries are vendored -- see ROADMAP.md/the
|
|
# PR discussion for why that was declined for now).
|
|
test:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: golang:1.26.6-bookworm
|
|
volumes:
|
|
- go-mod-cache:/go/pkg/mod
|
|
- go-build-cache:/root/.cache/go-build
|
|
- gobin-cache:/go/bin
|
|
|
|
steps:
|
|
- name: Checkout
|
|
env:
|
|
REF_NAME: ${{ github.ref_name }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: |
|
|
if [ -n "$HEAD_SHA" ]; then
|
|
# A pull_request ref_name is "<n>/merge", which is not a fetchable branch.
|
|
git clone "$REPO_URL" .
|
|
git checkout -q "$HEAD_SHA"
|
|
else
|
|
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
|
fi
|
|
|
|
- name: Format, lint and test
|
|
# TEMPORARY: `lint` is blocked by an unrelated github.com git-clone failure
|
|
# (golangci-lint's own custom-gcl build), which never lets this reach `test`'s
|
|
# setup-envtest step -- the one the act-runner MTU fix (Ryuvia/charts#272) was
|
|
# actually meant to affect. Narrowed to `test` alone to get a clean read on
|
|
# that specific question; revert to `make fmt lint test` once answered.
|
|
run: make test
|
|
|
|
# No `chart` job yet -- there's no Helm chart until Stage 6 (ROADMAP.md). No
|
|
# `security` job yet either (govulncheck/gitleaks, as terdut-server has); add one
|
|
# alongside `test` once there's controller code worth scanning.
|