Drive the pipeline through make, the way riksdata and rd-web do
Both workflows restated the build in YAML: gofmt, go vet and go test inline
in two places, buildx inline in a third, and the chart's version sed'd into
Chart.yaml before packaging. The Makefile added in 1081260 then described
the same checks a second time for local use, which made "green locally means
green in CI" a promise about keeping two files in step rather than a
property of the setup.
riksdata and rd-web never had that problem — their workflows call make and
have done all along. This repo was the odd one out, and only because it had
no Makefile until today. Now ci.yaml runs `make fmt lint test`, release.yaml
runs the same plus `make binaries`, `make push`, `make helm-package` and
`make helm-push`, and the reasoning behind each check lives on the target
rather than in whichever YAML file was edited last.
Three things change rather than just move:
The chart is linted before it is published. release.yaml packaged and pushed
without ever rendering the templates, so a chart that did not compile would
have reached the registry and been found by Flux. ci.yaml gained a chart job
for the same reason.
helm package --version --app-version replaces the sed. The published
metadata is identical, but the tree is no longer mutated mid-build, and it
is what the rest of the release process already assumed happened.
`make push` refuses VERSION=dev. Publishing is one command now, so it is
also one command to run by accident; dev is not a version anyone releases.
Deliberately not moved: uploading the release assets. Compiling them is
`make binaries` and runs anywhere, but the upload needs a token and the
Gitea release API, which is the workflow's business and not something worth
a target.
`push` builds and pushes in one step, unlike riksdata's separate build and
push, because buildx cannot load a multi-platform image into the local store
— it can only push it. `build` stays single-platform and local-only.
Claude-Session: https://claude.ai/code/session_01S7R4gWTz5wh5xCY4nCSJjN
This commit is contained in:
+32
-25
@@ -59,32 +59,39 @@ jobs:
|
||||
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
||||
fi
|
||||
|
||||
# This exists because `go vet` does not look at import order: the move to
|
||||
# git.ryuvia.com rewrote every import path without re-sorting, the new path sorts
|
||||
# before github.com/..., and both repos sat unformatted through a green CI run and
|
||||
# a release before anyone noticed.
|
||||
# The gate is the Makefile's rather than a second copy of it here, the way riksdata
|
||||
# and rd-web already do it. `make fmt lint test` is exactly what a developer runs, so
|
||||
# a green pipeline and a green working copy mean the same thing by construction
|
||||
# instead of by remembering to update two files together.
|
||||
#
|
||||
# Both of gofmt's failure modes need handling, and they are not alike. A file that
|
||||
# is merely misformatted is listed on stdout with exit 0 -- so the failure has to
|
||||
# be raised by hand. A file that does not parse is the opposite: nothing on stdout
|
||||
# and exit 2, which a naive `[ -n "$unformatted" ]` reads as success. The first
|
||||
# draft of this step had exactly that hole.
|
||||
- name: Format
|
||||
# The reasoning that used to live here moved with the targets: why gofmt is checked
|
||||
# at all (import order survives `go vet`, and both repos sat unformatted through a
|
||||
# green run and a release -- 9046f6e), why both of gofmt's failure modes need
|
||||
# handling, and why `test` adds -race when this job does not have to.
|
||||
- name: Format, vet and test
|
||||
run: make fmt lint test
|
||||
|
||||
# Host mode, no `container:`: helm is baked into the runner image, and a container job
|
||||
# could not install it -- get.helm.sh is unreachable from the dind bridge. Same reason
|
||||
# release.yaml's chart job runs on the host.
|
||||
#
|
||||
# The chart had no lint step in any workflow until 2026-09-01: release.yaml packaged and
|
||||
# pushed it without rendering it first, so a template that did not compile would have
|
||||
# been found by Flux rather than here.
|
||||
chart:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout
|
||||
env:
|
||||
REF_NAME: ${{ github.ref_name }}
|
||||
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
||||
run: |
|
||||
if ! unformatted=$(gofmt -l .); then
|
||||
echo "::error::gofmt could not parse the tree"
|
||||
gofmt -l . # re-run unredirected so the parse errors reach the log
|
||||
exit 1
|
||||
fi
|
||||
if [ -n "$unformatted" ]; then
|
||||
echo "::error::not gofmt'd:"
|
||||
echo "$unformatted"
|
||||
gofmt -d .
|
||||
exit 1
|
||||
if [ -n "$HEAD_SHA" ]; then
|
||||
git clone "$REPO_URL" .
|
||||
git checkout -q "$HEAD_SHA"
|
||||
else
|
||||
git clone --depth=1 --branch "$REF_NAME" "$REPO_URL" .
|
||||
fi
|
||||
|
||||
- name: Vet
|
||||
run: go vet ./...
|
||||
|
||||
- name: Test
|
||||
run: go test ./...
|
||||
- name: Lint and render the chart
|
||||
run: make helm-lint
|
||||
|
||||
Reference in New Issue
Block a user