Adds three lint jobs (actionlint, shellcheck, compose) and a server-side dry-run of the active manifests. Previously the only k8s check was kubeconform, which has no schemas for CRDs, so every IngressRoute, Certificate, PrometheusRule and Middleware was silently skipped. The server-side pass needs the live API server because that is the only place the real CRD schemas and the cert-manager / Traefik admission webhooks exist. It is scoped to services carrying a k8s/active marker, since dry-run needs the target namespace to exist. userbot/ is excluded from shellcheck: it is a git subtree, and linting upstream's scripts would let a routine subtree pull turn the deploy gate red on code we do not own. kubeconform, shellcheck and actionlint are now installed from pinned versions in tool-versions.env rather than picked up from the runner's PATH. The Compose helper is shared with the deploy workflow so both check the same file set the same way.
10 lines
416 B
Bash
10 lines
416 B
Bash
# Pinned versions of the CI linters installed by install-ci-tools.sh.
|
|
# Renovate keeps these up to date (see customManagers in renovate/renovate.json).
|
|
#
|
|
# The renovate image version is NOT pinned here: renovate/k8s/cronjob.yaml is the
|
|
# single source of truth and the workflows read the tag from it, so there is
|
|
# nothing to drift.
|
|
ACTIONLINT_VERSION="1.7.7"
|
|
SHELLCHECK_VERSION="0.11.0"
|
|
KUBECONFORM_VERSION="0.8.0"
|