fix(deploy): validate compose without workstation secrets
deploy / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
ci / lint-prettier (push) Successful in 2s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
deploy / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
ci / lint-prettier (push) Successful in 2s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped
docker compose config required real values for gitignored .env files and secrets, so validate always failed on stacks with :? guards (netbird, netbox). Validate structure only via --no-interpolate, --no-env-resolution and --no-path-resolution, keeping normalization and consistency checks.
This commit is contained in:
1 parent
27ab6b859e
commit
a2ff9515a3
1 file changed
+18
-1
@@ -89,10 +89,27 @@ stage_validate() {
|
|||||||
cd "$REPO"
|
cd "$REPO"
|
||||||
select_manifests
|
select_manifests
|
||||||
local m k cf
|
local m k cf
|
||||||
|
# Compose .env files and secret files are gitignored by design, so the
|
||||||
|
# workstation never has real values for them. Validate structure only:
|
||||||
|
# skip interpolation, env-file resolution, and path resolution so that
|
||||||
|
# required-variable guards (:?) and missing local files don't fail CI.
|
||||||
|
# Normalization and consistency checks stay enabled.
|
||||||
|
local compose_validate_flags=()
|
||||||
|
local compose_config_help
|
||||||
|
compose_config_help="$(docker compose config --help 2>/dev/null || true)"
|
||||||
|
if printf '%s' "$compose_config_help" | grep -q -- '--no-interpolate'; then
|
||||||
|
compose_validate_flags+=(--no-interpolate)
|
||||||
|
fi
|
||||||
|
if printf '%s' "$compose_config_help" | grep -q -- '--no-env-resolution'; then
|
||||||
|
compose_validate_flags+=(--no-env-resolution)
|
||||||
|
fi
|
||||||
|
if printf '%s' "$compose_config_help" | grep -q -- '--no-path-resolution'; then
|
||||||
|
compose_validate_flags+=(--no-path-resolution)
|
||||||
|
fi
|
||||||
log "Validate compose stacks"
|
log "Validate compose stacks"
|
||||||
for cf in ${COMPOSE_STACKS[@]+"${COMPOSE_STACKS[@]}"}; do
|
for cf in ${COMPOSE_STACKS[@]+"${COMPOSE_STACKS[@]}"}; do
|
||||||
echo " config: $cf"
|
echo " config: $cf"
|
||||||
docker compose -f "$cf" config --quiet
|
docker compose -f "$cf" config --quiet "${compose_validate_flags[@]}"
|
||||||
done
|
done
|
||||||
log "Validate k8s manifests (kubectl dry-run=client)"
|
log "Validate k8s manifests (kubectl dry-run=client)"
|
||||||
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
||||||
|
|||||||
Reference in new issue
Block a user