b4ccdb09d5
Release / test (push) Successful in 2m48s
CI / chart (push) Successful in 1s
CI / security (push) Successful in 1m3s
CI / test (push) Successful in 2m5s
Release / chart (push) Successful in 4s
Release / image (push) Successful in 7m6s
Release / scan-image (push) Failing after 33s
Chart (charts/terdut-operator) generated via kubebuilder's own helm/v2-alpha plugin from config/'s kustomize output -- CRDs + manager Deployment/RBAC come from the same markers every other stage already generates, one source of truth. Hand-added on top: the optional terdutServer values block (DESIGN.md §10's "helm install and get a server" path, off by default) and the release-skill plumbing -- .release.conf, release-vars/helm-lint/push/ helm-package/helm-push/release Makefile targets, .gitea/workflows/release.yaml (test -> image/chart -> scan-image) -- mirroring terdut-server's own shape (registry/namespace convention, multi-arch buildx push, trivy/govulncheck/ gitleaks scans). ci.yaml gains security and chart jobs to match. Two real issues caught while wiring this, fixed before either shipped: - Dockerfile's builder stage didn't pin --platform=$BUILDPLATFORM, which would have made a multi-arch release build fail outright on this org's runners (no binfmt registration) -- same fix terdut-server's own Dockerfile already needed for the same reason. - govulncheck found one real, reachable finding: google.golang.org/grpc v1.82.1 (transitive via controller-runtime's otel exporter), fixed by bumping to v1.83.1. Full golden-path kind e2e pass, this time through `helm install` rather than raw kustomize: TerdutServer (real terdut-server v0.33.0 image) -> TerdutTeam -> one of each child kind, each confirmed Ready and then independently confirmed against terdut-server's own API from inside the cluster (not just the operator's own status). Deleted every CR in reverse order and confirmed server-side cleanup the same independent way for all three child kinds, the team, and the server. No new bugs found -- Stage 1's own kind pass already caught what a real cluster catches that envtest can't. Also dropped the kubebuilder helm plugin's default .github/workflows/ scaffold, same as Stage 0 already did for the main scaffold: this org runs on Gitea, not GitHub. Not done here, deliberately: an actual tagged release. release-preflight found no terdut-operator/ entry under Ryuvia/charts yet to bump -- that one-time wrapper bootstrap is a decision about deploying this operator for real, not a side effect of finishing this stage. make fmt lint test helm-lint build all clean.
449 lines
20 KiB
Makefile
449 lines
20 KiB
Makefile
# Image URL to use all building/pushing image targets
|
|
IMG ?= controller:latest
|
|
# YEAR defines the year value used for substituting the YEAR placeholder in the boilerplate header.
|
|
YEAR ?= $(shell date +%Y)
|
|
|
|
# Get the currently used golang install path (in GOPATH/bin, unless GOBIN is set)
|
|
ifeq (,$(shell go env GOBIN))
|
|
GOBIN=$(shell go env GOPATH)/bin
|
|
else
|
|
GOBIN=$(shell go env GOBIN)
|
|
endif
|
|
|
|
# CONTAINER_TOOL defines the container tool to be used for building images.
|
|
# Be aware that the target commands are only tested with Docker which is
|
|
# scaffolded by default. However, you might want to replace it to use other
|
|
# tools. (i.e. podman)
|
|
CONTAINER_TOOL ?= docker
|
|
|
|
# Setting SHELL to bash allows bash commands to be executed by recipes.
|
|
# Options are set to exit when a recipe line exits non-zero or a piped command fails.
|
|
SHELL = /usr/bin/env bash -o pipefail
|
|
.SHELLFLAGS = -ec
|
|
|
|
.PHONY: all
|
|
all: build
|
|
|
|
##@ General
|
|
|
|
# The help target prints out all targets with their descriptions organized
|
|
# beneath their categories. The categories are represented by '##@' and the
|
|
# target descriptions by '##'. The awk command is responsible for reading the
|
|
# entire set of makefiles included in this invocation, looking for lines of the
|
|
# file as xyz: ## something, and then pretty-format the target and help. Then,
|
|
# if there's a line with ##@ something, that gets pretty-printed as a category.
|
|
# More info on the usage of ANSI control characters for terminal formatting:
|
|
# https://en.wikipedia.org/wiki/ANSI_escape_code#SGR_parameters
|
|
# More info on the awk command:
|
|
# http://linuxcommand.org/lc3_adv_awk.php
|
|
|
|
.PHONY: help
|
|
help: ## Display this help.
|
|
@awk 'BEGIN {FS = ":.*##"; printf "\nUsage:\n make \033[36m<target>\033[0m\n"} /^[a-zA-Z_0-9-]+:.*?##/ { printf " \033[36m%-15s\033[0m %s\n", $$1, $$2 } /^##@/ { printf "\n\033[1m%s\033[0m\n", substr($$0, 5) } ' $(MAKEFILE_LIST)
|
|
|
|
##@ Development
|
|
|
|
.PHONY: manifests
|
|
manifests: controller-gen ## Generate WebhookConfiguration, ClusterRole and CustomResourceDefinition objects.
|
|
"$(CONTROLLER_GEN)" rbac:roleName=manager-role crd webhook paths="./..." output:crd:artifacts:config=config/crd/bases
|
|
|
|
.PHONY: generate
|
|
generate: controller-gen ## Generate code containing DeepCopy, DeepCopyInto, and DeepCopyObject method implementations.
|
|
"$(CONTROLLER_GEN)" object paths="./..."
|
|
|
|
.PHONY: fmt
|
|
fmt: ## Run go fmt against code.
|
|
go fmt ./...
|
|
|
|
.PHONY: vet
|
|
vet: ## Run go vet against code.
|
|
go vet ./...
|
|
|
|
.PHONY: test
|
|
test: manifests generate fmt vet setup-envtest ## Run tests.
|
|
KUBEBUILDER_ASSETS="$(shell "$(ENVTEST)" use $(ENVTEST_K8S_VERSION) --bin-dir "$(LOCALBIN)" -p path)" go test $$(go list ./... | grep -v /e2e) -coverprofile cover.out
|
|
|
|
# TODO(user): To use a different vendor for e2e tests, modify the setup under 'tests/e2e'.
|
|
# The default setup assumes Kind is pre-installed and builds/loads the Manager Docker image locally.
|
|
# kubectl kuberc is disabled by default for test isolation; enable with:
|
|
# - KUBECTL_KUBERC=true
|
|
# CertManager is installed by default; skip with:
|
|
# - CERT_MANAGER_INSTALL_SKIP=true
|
|
KIND_CLUSTER ?= terdut-operator-test-e2e
|
|
|
|
.PHONY: setup-test-e2e
|
|
setup-test-e2e: ## Set up a Kind cluster for e2e tests if it does not exist
|
|
@command -v $(KIND) >/dev/null 2>&1 || { \
|
|
echo "Kind is not installed. Please install Kind manually."; \
|
|
exit 1; \
|
|
}
|
|
@case "$$($(KIND) get clusters)" in \
|
|
*"$(KIND_CLUSTER)"*) \
|
|
echo "Kind cluster '$(KIND_CLUSTER)' already exists. Skipping creation." ;; \
|
|
*) \
|
|
echo "Creating Kind cluster '$(KIND_CLUSTER)'..."; \
|
|
$(KIND) create cluster --name $(KIND_CLUSTER) ;; \
|
|
esac
|
|
|
|
.PHONY: test-e2e
|
|
test-e2e: setup-test-e2e manifests generate fmt vet ## Run the e2e tests. Expected an isolated environment using Kind.
|
|
KIND=$(KIND) KIND_CLUSTER=$(KIND_CLUSTER) go test -tags=e2e ./test/e2e/ -v -ginkgo.v
|
|
$(MAKE) cleanup-test-e2e
|
|
|
|
.PHONY: cleanup-test-e2e
|
|
cleanup-test-e2e: ## Tear down the Kind cluster used for e2e tests
|
|
@$(KIND) delete cluster --name $(KIND_CLUSTER)
|
|
|
|
.PHONY: lint
|
|
lint: golangci-lint ## Run golangci-lint linter
|
|
"$(GOLANGCI_LINT)" run
|
|
|
|
.PHONY: lint-fix
|
|
lint-fix: golangci-lint ## Run golangci-lint linter and perform fixes
|
|
"$(GOLANGCI_LINT)" run --fix
|
|
|
|
.PHONY: lint-config
|
|
lint-config: golangci-lint ## Verify golangci-lint linter configuration
|
|
"$(GOLANGCI_LINT)" config verify
|
|
|
|
##@ Build
|
|
|
|
.PHONY: build
|
|
build: manifests generate fmt vet ## Build manager binary.
|
|
go build -o bin/manager cmd/main.go
|
|
|
|
.PHONY: run
|
|
run: manifests generate fmt vet ## Run a controller from your host.
|
|
go run ./cmd/main.go
|
|
|
|
# If you wish to build the manager image targeting other platforms you can use the --platform flag.
|
|
# (i.e. docker build --platform linux/arm64). However, you must enable docker buildKit for it.
|
|
# More info: https://docs.docker.com/develop/develop-images/build_enhancements/
|
|
# Override BASE_IMAGE to build from another registry, e.g.
|
|
# make docker-build IMG=<img> BASE_IMAGE=docker.io/library/golang:1.26
|
|
.PHONY: docker-build
|
|
docker-build: ## Build docker image with the manager.
|
|
$(CONTAINER_TOOL) build $(if $(BASE_IMAGE),--build-arg BASE_IMAGE=$(BASE_IMAGE)) -t ${IMG} .
|
|
|
|
.PHONY: docker-push
|
|
docker-push: ## Push docker image with the manager.
|
|
$(CONTAINER_TOOL) push ${IMG}
|
|
|
|
# PLATFORMS defines the target platforms for the manager image be built to provide support to multiple
|
|
# architectures. (i.e. make docker-buildx IMG=myregistry/mypoperator:0.0.1). To use this option you need to:
|
|
# - be able to use docker buildx. More info: https://docs.docker.com/build/buildx/
|
|
# - have enabled BuildKit. More info: https://docs.docker.com/develop/develop-images/build_enhancements/
|
|
# - be able to push the image to your registry (i.e. if you do not set a valid value via IMG=<myregistry/image:<tag>> then the export will fail)
|
|
# To adequately provide solutions that are compatible with multiple platforms, you should consider using this option.
|
|
PLATFORMS ?= linux/arm64,linux/amd64,linux/s390x,linux/ppc64le
|
|
.PHONY: docker-buildx
|
|
docker-buildx: ## Build and push docker image for the manager for cross-platform support
|
|
# copy existing Dockerfile and insert --platform=${BUILDPLATFORM} into Dockerfile.cross, and preserve the original Dockerfile
|
|
sed -e '1 s/\(^FROM\)/FROM --platform=\$$\{BUILDPLATFORM\}/; t' -e ' 1,// s//FROM --platform=\$$\{BUILDPLATFORM\}/' Dockerfile > Dockerfile.cross
|
|
- $(CONTAINER_TOOL) buildx create --name terdut-operator-builder
|
|
$(CONTAINER_TOOL) buildx use terdut-operator-builder
|
|
- $(CONTAINER_TOOL) buildx build --push --platform=$(PLATFORMS) $(if $(BASE_IMAGE),--build-arg BASE_IMAGE=$(BASE_IMAGE)) --tag ${IMG} -f Dockerfile.cross .
|
|
- $(CONTAINER_TOOL) buildx rm terdut-operator-builder
|
|
rm Dockerfile.cross
|
|
|
|
.PHONY: build-installer
|
|
build-installer: manifests generate kustomize ## Generate a consolidated YAML with CRDs and deployment.
|
|
mkdir -p dist
|
|
cd config/manager && "$(KUSTOMIZE)" edit set image controller=${IMG}
|
|
"$(KUSTOMIZE)" build config/default > dist/install.yaml
|
|
|
|
##@ Deployment
|
|
|
|
ifndef ignore-not-found
|
|
ignore-not-found = false
|
|
endif
|
|
|
|
.PHONY: install
|
|
install: manifests kustomize ## Install CRDs into the K8s cluster specified in ~/.kube/config.
|
|
@out="$$( "$(KUSTOMIZE)" build config/crd 2>/dev/null || true )"; \
|
|
if [ -n "$$out" ]; then echo "$$out" | "$(KUBECTL)" apply -f -; else echo "No CRDs to install; skipping."; fi
|
|
|
|
.PHONY: uninstall
|
|
uninstall: manifests kustomize ## Uninstall CRDs from the K8s cluster specified in ~/.kube/config. Call with ignore-not-found=true to ignore resource not found errors during deletion.
|
|
@out="$$( "$(KUSTOMIZE)" build config/crd 2>/dev/null || true )"; \
|
|
if [ -n "$$out" ]; then echo "$$out" | "$(KUBECTL)" delete --ignore-not-found=$(ignore-not-found) -f -; else echo "No CRDs to delete; skipping."; fi
|
|
|
|
.PHONY: deploy
|
|
deploy: manifests kustomize ## Deploy controller to the K8s cluster specified in ~/.kube/config.
|
|
cd config/manager && "$(KUSTOMIZE)" edit set image controller=${IMG}
|
|
"$(KUSTOMIZE)" build config/default | "$(KUBECTL)" apply -f -
|
|
|
|
.PHONY: undeploy
|
|
undeploy: kustomize ## Undeploy controller from the K8s cluster specified in ~/.kube/config. Call with ignore-not-found=true to ignore resource not found errors during deletion.
|
|
"$(KUSTOMIZE)" build config/default | "$(KUBECTL)" delete --ignore-not-found=$(ignore-not-found) -f -
|
|
|
|
##@ Dependencies
|
|
|
|
## Location to install dependencies to
|
|
LOCALBIN ?= $(shell pwd)/bin
|
|
$(LOCALBIN):
|
|
mkdir -p "$(LOCALBIN)"
|
|
|
|
## Tool Binaries
|
|
KUBECTL ?= kubectl
|
|
KIND ?= kind
|
|
KUSTOMIZE ?= $(LOCALBIN)/kustomize
|
|
CONTROLLER_GEN ?= $(LOCALBIN)/controller-gen
|
|
ENVTEST ?= $(LOCALBIN)/setup-envtest
|
|
GOLANGCI_LINT = $(LOCALBIN)/golangci-lint
|
|
|
|
## Tool Versions
|
|
KUSTOMIZE_VERSION ?= v5.8.1
|
|
CONTROLLER_TOOLS_VERSION ?= v0.22.0
|
|
|
|
#ENVTEST_VERSION is the controller-runtime version to use for setup-envtest, derived from go.mod
|
|
ENVTEST_VERSION ?= $(shell v='$(call gomodver,sigs.k8s.io/controller-runtime)'; \
|
|
[ -n "$$v" ] || { echo "Set ENVTEST_VERSION manually (controller-runtime replace has no tag)" >&2; exit 1; }; \
|
|
printf '%s\n' "$$v")
|
|
|
|
#ENVTEST_K8S_VERSION is the version of Kubernetes to use for setting up ENVTEST binaries (i.e. 1.31)
|
|
ENVTEST_K8S_VERSION ?= $(shell v='$(call gomodver,k8s.io/api)'; \
|
|
[ -n "$$v" ] || { echo "Set ENVTEST_K8S_VERSION manually (k8s.io/api replace has no tag)" >&2; exit 1; }; \
|
|
printf '%s\n' "$$v" | sed -E 's/^v?[0-9]+\.([0-9]+).*/1.\1/')
|
|
|
|
GOLANGCI_LINT_VERSION ?= v2.13.1
|
|
.PHONY: kustomize
|
|
kustomize: $(KUSTOMIZE) ## Download kustomize locally if necessary.
|
|
$(KUSTOMIZE): $(LOCALBIN)
|
|
$(call go-install-tool,$(KUSTOMIZE),sigs.k8s.io/kustomize/kustomize/v5,$(KUSTOMIZE_VERSION))
|
|
|
|
.PHONY: controller-gen
|
|
controller-gen: $(CONTROLLER_GEN) ## Download controller-gen locally if necessary.
|
|
$(CONTROLLER_GEN): $(LOCALBIN)
|
|
$(call go-install-tool,$(CONTROLLER_GEN),sigs.k8s.io/controller-tools/cmd/controller-gen,$(CONTROLLER_TOOLS_VERSION))
|
|
|
|
.PHONY: setup-envtest
|
|
setup-envtest: envtest ## Download the binaries required for ENVTEST in the local bin directory.
|
|
@echo "Setting up envtest binaries for Kubernetes version $(ENVTEST_K8S_VERSION)..."
|
|
@"$(ENVTEST)" use $(ENVTEST_K8S_VERSION) --bin-dir "$(LOCALBIN)" -p path || { \
|
|
echo "Error: Failed to set up envtest binaries for version $(ENVTEST_K8S_VERSION)."; \
|
|
exit 1; \
|
|
}
|
|
|
|
.PHONY: envtest
|
|
envtest: $(ENVTEST) ## Download setup-envtest locally if necessary.
|
|
$(ENVTEST): $(LOCALBIN)
|
|
$(call go-install-tool,$(ENVTEST),sigs.k8s.io/controller-runtime/tools/setup-envtest,$(ENVTEST_VERSION))
|
|
|
|
.PHONY: golangci-lint
|
|
golangci-lint: $(GOLANGCI_LINT) ## Download golangci-lint locally if necessary.
|
|
$(GOLANGCI_LINT): $(LOCALBIN)
|
|
$(call go-install-tool,$(GOLANGCI_LINT),github.com/golangci/golangci-lint/v2/cmd/golangci-lint,$(GOLANGCI_LINT_VERSION))
|
|
@test -f .custom-gcl.yml && { \
|
|
echo "Building custom golangci-lint with plugins..." && \
|
|
$(GOLANGCI_LINT) custom --destination $(LOCALBIN) --name golangci-lint-custom && \
|
|
mv -f $(LOCALBIN)/golangci-lint-custom $(GOLANGCI_LINT); \
|
|
} || true
|
|
|
|
# go-install-tool will 'go install' any package with custom target and name of binary, if it doesn't exist
|
|
# $1 - target path with name of binary
|
|
# $2 - package url which can be installed
|
|
# $3 - specific version of package
|
|
define go-install-tool
|
|
@[ -f "$(1)-$(3)" ] && [ "$$(readlink -- "$(1)" 2>/dev/null)" = "$(1)-$(3)" ] || { \
|
|
set -e; \
|
|
package=$(2)@$(3) ;\
|
|
echo "Downloading $${package}" ;\
|
|
rm -f "$(1)" ;\
|
|
GOBIN="$(LOCALBIN)" go install $${package} ;\
|
|
mv "$(LOCALBIN)/$$(basename "$(1)")" "$(1)-$(3)" ;\
|
|
} ;\
|
|
ln -sf "$$(realpath "$(1)-$(3)")" "$(1)"
|
|
endef
|
|
|
|
define gomodver
|
|
$(shell go list -m -f '{{if .Replace}}{{.Replace.Version}}{{else}}{{.Version}}{{end}}' $(1) 2>/dev/null)
|
|
endef
|
|
|
|
##@ Helm Deployment
|
|
|
|
## Helm binary to use for deploying the chart
|
|
HELM ?= helm
|
|
## Namespace to deploy the Helm release
|
|
HELM_NAMESPACE ?= terdut-operator-system
|
|
## Name of the Helm release
|
|
HELM_RELEASE ?= terdut-operator
|
|
## Path to the Helm chart directory. Must stay equal to HELM_CHART below
|
|
## (the release process's own name for this same path) -- two variables
|
|
## because this one is kubebuilder's own scaffold and that one is the
|
|
## release skill's contract, not because the path differs.
|
|
HELM_CHART_DIR ?= charts/terdut-operator
|
|
## Additional arguments to pass to helm commands
|
|
HELM_EXTRA_ARGS ?=
|
|
|
|
.PHONY: install-helm
|
|
install-helm: ## Install the latest version of Helm.
|
|
@command -v $(HELM) >/dev/null 2>&1 || { \
|
|
echo "Installing Helm..." && \
|
|
curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-4 | bash; \
|
|
}
|
|
|
|
.PHONY: helm-deploy
|
|
helm-deploy: install-helm ## Deploy manager to the K8s cluster via Helm. Specify an image with IMG.
|
|
IMG="$(IMG)"; $(HELM) upgrade --install $(HELM_RELEASE) $(HELM_CHART_DIR) \
|
|
--namespace $(HELM_NAMESPACE) \
|
|
--create-namespace \
|
|
--set manager.image.repository=$${IMG%:*} \
|
|
--set manager.image.tag=$${IMG##*:} \
|
|
--wait \
|
|
--timeout 5m \
|
|
$(HELM_EXTRA_ARGS)
|
|
|
|
.PHONY: helm-uninstall
|
|
helm-uninstall: ## Uninstall the Helm release from the K8s cluster.
|
|
$(HELM) uninstall $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
|
|
|
.PHONY: helm-status
|
|
helm-status: ## Show Helm release status.
|
|
$(HELM) status $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
|
|
|
.PHONY: helm-history
|
|
helm-history: ## Show Helm release history.
|
|
$(HELM) history $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
|
|
|
.PHONY: helm-rollback
|
|
helm-rollback: ## Rollback to previous Helm release.
|
|
$(HELM) rollback $(HELM_RELEASE) --namespace $(HELM_NAMESPACE)
|
|
|
|
##@ Release
|
|
|
|
# Everything below is read by the `release` skill (~/.claude/skills/release), not by
|
|
# anything above it in this file -- mirrors terdut-server's Makefile section for
|
|
# section, adapted for this repo (no Postgres service for tests, no CLI binaries to
|
|
# cross-compile, one image + one chart to publish).
|
|
|
|
REGISTRY := git.ryuvia.com
|
|
# The personal namespace, not ryuvia -- same reasoning as terdut-server: Gitea scopes
|
|
# package visibility to the owner with no per-package override, so publishing here
|
|
# keeps the image and chart anonymously pullable and Flux needs no registry
|
|
# credentials to pull them.
|
|
OWNER := niklas
|
|
|
|
IMAGE := $(REGISTRY)/$(OWNER)/terdut-operator
|
|
HELM_CHART := charts/terdut-operator
|
|
HELM_REPO := oci://$(REGISTRY)/$(OWNER)
|
|
|
|
.PHONY: release-vars
|
|
release-vars: ## Print the variables the release process reads
|
|
@printf 'IMAGE=%s\nHELM_CHART=%s\nHELM_REPO=%s\n' '$(IMAGE)' '$(HELM_CHART)' '$(HELM_REPO)'
|
|
|
|
# database is required (dsn xor postgresClusterRef, DatabaseSpec's own CEL rule) once
|
|
# terdutServer.enabled, so the chart's own `required` calls fail a bare
|
|
# `--set terdutServer.enabled=true` the same way a real install without a database
|
|
# would be rejected at apply time -- this set gives that path something valid to
|
|
# render against, the way terdut-server's own HELM_LINT_SET supplies its one
|
|
# required field (database.dsn) for the same reason.
|
|
HELM_LINT_SET = --set terdutServer.enabled=true \
|
|
--set terdutServer.image.tag=v0.0.0 \
|
|
--set terdutServer.networking.hostname=terdut.example.invalid \
|
|
--set 'terdutServer.database.dsn=postgres://terdut@terdut-postgres:5432/terdut?sslmode=require'
|
|
|
|
.PHONY: helm-lint
|
|
helm-lint: ## Lint and render the chart
|
|
helm lint $(HELM_CHART)
|
|
helm template terdut-operator $(HELM_CHART) --namespace terdut-operator-system >/dev/null
|
|
# Second pass: the optional TerdutServer CR template (off by default, so the
|
|
# bare render above never exercises it at all).
|
|
helm lint $(HELM_CHART) $(HELM_LINT_SET)
|
|
helm template terdut-operator $(HELM_CHART) --namespace terdut-operator-system \
|
|
$(HELM_LINT_SET) >/dev/null
|
|
|
|
## --- publishing ---
|
|
#
|
|
# Exist so .gitea/workflows/release.yaml can call `make push` / `make helm-package
|
|
# helm-push` instead of restating the build in YAML -- one definition, runnable
|
|
# locally, reviewable in a diff. Publishing happens by pushing a tag; nothing else.
|
|
#
|
|
# VERSION is the git tag, passed in by the workflow. require-version is why a stray
|
|
# local `make push` cannot publish: dev is not a version anyone releases.
|
|
|
|
VERSION ?= dev
|
|
|
|
# Helm requires strict SemVer -- strip a leading 'v' if present.
|
|
CHART_VERSION := $(shell echo "$(VERSION)" | sed 's/^v//')
|
|
|
|
# Named RELEASE_PLATFORMS, not PLATFORMS: that name is already taken above by
|
|
# kubebuilder's own docker-buildx target (a 4-platform list this repo's own release
|
|
# process doesn't use), and `?=` on an already-set variable is a silent no-op, not an
|
|
# override -- reusing it here would have quietly built s390x/ppc64le instead of the
|
|
# two platforms this target actually intends.
|
|
RELEASE_PLATFORMS ?= linux/amd64,linux/arm64
|
|
BUILDX_BUILDER ?= terdut-operator-release
|
|
|
|
# An isolated repo list, same reasoning as terdut-server's: the machine-wide one is
|
|
# not this build's business, and one unreachable entry in it aborts otherwise-fine
|
|
# helm commands. HELM_REPOSITORY_CACHE is deliberately NOT overridden alongside it --
|
|
# helm writes a refreshed index to the default cache and then looks for it there.
|
|
HELM_ISOLATED = HELM_REPOSITORY_CONFIG=$(CURDIR)/.helm-repos.yaml
|
|
|
|
.PHONY: require-version
|
|
require-version:
|
|
@test "$(VERSION)" != "dev" || \
|
|
(echo "VERSION=dev names no release -- pass VERSION=vX.Y.Z (the workflow passes the tag)" && exit 1)
|
|
|
|
# Multi-arch, so this is build-and-push in one step, same reasoning as
|
|
# terdut-server's own `push`: buildx cannot load a multi-platform result into the
|
|
# local image store, so there is no separate local-only `build` target here either.
|
|
#
|
|
# No QEMU: the Dockerfile's builder stage runs on $$BUILDPLATFORM and cross-compiles
|
|
# via GOOS/GOARCH, so both platforms build natively -- same fix as terdut-server's
|
|
# Dockerfile, for the same reason (this CI runner has no binfmt registration).
|
|
.PHONY: push
|
|
push: require-version ## Build and publish the multi-arch image
|
|
docker buildx create --name $(BUILDX_BUILDER) --use 2>/dev/null || docker buildx use $(BUILDX_BUILDER)
|
|
docker buildx build \
|
|
--platform $(RELEASE_PLATFORMS) \
|
|
--tag "$(IMAGE):latest" \
|
|
--tag "$(IMAGE):$(VERSION)" \
|
|
--push .
|
|
|
|
# --version/--app-version come from the tag, so Chart.yaml's own fields decide
|
|
# nothing about what gets published -- same as terdut-server's chart.
|
|
.PHONY: helm-package
|
|
helm-package: require-version ## Package the chart, versioned from the tag
|
|
$(HELM_ISOLATED) helm package $(HELM_CHART) \
|
|
--version $(CHART_VERSION) \
|
|
--app-version $(VERSION) \
|
|
--destination dist
|
|
|
|
.PHONY: helm-push
|
|
helm-push: require-version ## Push the packaged chart to the OCI registry
|
|
$(HELM_ISOLATED) helm push dist/terdut-operator-$(CHART_VERSION).tgz $(HELM_REPO)
|
|
|
|
.PHONY: release
|
|
release: push helm-package helm-push ## Publish image + chart (the workflow's one call)
|
|
|
|
## --- security ---
|
|
|
|
GOVULNCHECK_VERSION := v1.1.4
|
|
GITLEAKS_VERSION := v8.30.0
|
|
TRIVY_VERSION := 0.73.0
|
|
|
|
# Symbol-level, not dependency-level, same as terdut-server: govulncheck reports a
|
|
# vulnerability only when the code can actually reach it.
|
|
.PHONY: security-go
|
|
security-go: ## Scan Go deps for known CVEs (govulncheck)
|
|
go run golang.org/x/vuln/cmd/govulncheck@$(GOVULNCHECK_VERSION) ./...
|
|
|
|
# --no-git scans the working tree rather than the history, so this catches a secret
|
|
# on the way in; it says nothing about what is already committed.
|
|
.PHONY: security-secrets
|
|
security-secrets: ## Scan the working tree for committed secrets (gitleaks)
|
|
go run github.com/zricethezav/gitleaks/v8@$(GITLEAKS_VERSION) detect --no-git \
|
|
--source . --redact --no-banner --exit-code 1
|
|
|
|
# Scans the pushed image, not a local one -- trivy cannot read a locally built image
|
|
# on this runner, same reasoning as terdut-server. A red scan means: do not bump the
|
|
# wrapper chart in Ryuvia/charts to this version; it does not unpublish anything.
|
|
.PHONY: security-image
|
|
security-image: require-version ## Scan the pushed image for CVEs (needs VERSION)
|
|
docker run --rm -e TRIVY_USERNAME -e TRIVY_PASSWORD \
|
|
-v trivy-cache:/root/.cache/trivy \
|
|
docker.io/aquasec/trivy:$(TRIVY_VERSION) image --severity HIGH,CRITICAL \
|
|
--ignore-unfixed --exit-code 1 $(IMAGE):$(VERSION)
|