Adds three lint jobs (actionlint, shellcheck, compose) and a server-side dry-run of the active manifests. Previously the only k8s check was kubeconform, which has no schemas for CRDs, so every IngressRoute, Certificate, PrometheusRule and Middleware was silently skipped. The server-side pass needs the live API server because that is the only place the real CRD schemas and the cert-manager / Traefik admission webhooks exist. It is scoped to services carrying a k8s/active marker, since dry-run needs the target namespace to exist. userbot/ is excluded from shellcheck: it is a git subtree, and linting upstream's scripts would let a routine subtree pull turn the deploy gate red on code we do not own. kubeconform, shellcheck and actionlint are now installed from pinned versions in tool-versions.env rather than picked up from the runner's PATH. The Compose helper is shared with the deploy workflow so both check the same file set the same way.
11 lines
373 B
YAML
11 lines
373 B
YAML
# actionlint configuration. Passed explicitly from the ci workflow:
|
|
# actionlint -config-file .gitea/actionlint.yaml .gitea/workflows/*.yaml
|
|
#
|
|
# The self-hosted act_runner registers custom labels that actionlint cannot know
|
|
# about, so declare them here instead of silencing the whole runner-label check.
|
|
self-hosted-runner:
|
|
labels:
|
|
- arch
|
|
- homelab
|
|
- prod
|