Adds three lint jobs (actionlint, shellcheck, compose) and a server-side dry-run of the active manifests. Previously the only k8s check was kubeconform, which has no schemas for CRDs, so every IngressRoute, Certificate, PrometheusRule and Middleware was silently skipped. The server-side pass needs the live API server because that is the only place the real CRD schemas and the cert-manager / Traefik admission webhooks exist. It is scoped to services carrying a k8s/active marker, since dry-run needs the target namespace to exist. userbot/ is excluded from shellcheck: it is a git subtree, and linting upstream's scripts would let a routine subtree pull turn the deploy gate red on code we do not own. kubeconform, shellcheck and actionlint are now installed from pinned versions in tool-versions.env rather than picked up from the runner's PATH. The Compose helper is shared with the deploy workflow so both check the same file set the same way.
47 lines
1.8 KiB
Bash
47 lines
1.8 KiB
Bash
#!/usr/bin/env bash
|
|
# Shared helpers for validating Compose files. Sourced both by steps in
|
|
# .gitea/workflows/ci.yaml and by deploy-lib.sh on the workstation.
|
|
#
|
|
# Two levels of checking, matching how the repo is structured:
|
|
#
|
|
# general every committed Compose file, active or not. Pure structure check:
|
|
# no ${VAR} interpolation, no .env lookup, no bind-mount path
|
|
# resolution. Disabled stacks deliberately have no .env in the repo
|
|
# and no values on the CI runner, so a full `config` run would fail on
|
|
# their `${VAR:?}` guards for reasons that have nothing to do with the
|
|
# change under review.
|
|
#
|
|
# full active stacks only, with interpolation and env-file resolution, so
|
|
# required variables and referenced files are actually resolved. Needs
|
|
# the gitignored .env files, so this only runs in the deploy workflow
|
|
# on the workstation.
|
|
#
|
|
# This file is meant to be sourced, not executed.
|
|
|
|
# All committed Compose files, including the ones deploy never starts.
|
|
compose_files() {
|
|
git ls-files \
|
|
'*/compose.yaml' '*/compose.yml' 'compose.yaml' 'compose.yml' \
|
|
'*/docker-compose.yaml' '*/docker-compose.yml'
|
|
}
|
|
|
|
# Prints the flags that turn `docker compose config` into the general check.
|
|
# Probed rather than hardcoded so an older Compose without --no-env-resolution
|
|
# still gets the flags it does support.
|
|
compose_safe_flags() {
|
|
local help flag
|
|
help="$(docker compose config --help 2>/dev/null || true)"
|
|
for flag in --no-interpolate --no-env-resolution --no-path-resolution; do
|
|
if printf '%s' "$help" | grep -q -- "$flag"; then
|
|
printf '%s\n' "$flag"
|
|
fi
|
|
done
|
|
}
|
|
|
|
# validate_compose_file <file> [extra docker compose config flags...]
|
|
validate_compose_file() {
|
|
local file="$1"
|
|
shift
|
|
docker compose -f "$file" config --quiet "$@"
|
|
}
|