renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 5s
ci / lint-shellcheck (push) Failing after 10s
ci / lint-prettier (push) Successful in 13s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 11s
ci / lint-dockerfiles (push) Successful in 7s
ci / validate (push) Successful in 8s
ci / build (push) Skipped
ci / lint-compose (pull_request) Canceled after 0s
ci / lint-actionlint (pull_request) Canceled after 0s
ci / lint-shellcheck (pull_request) Canceled after 0s
ci / lint-prettier (pull_request) Canceled after 0s
ci / lint-ruff (pull_request) Canceled after 0s
ci / lint-yaml (pull_request) Canceled after 0s
ci / lint-dockerfiles (pull_request) Canceled after 0s
ci / validate (pull_request) Canceled after 0s
ci / build (pull_request) Canceled after 0s
renovate-ci / validate-renovate (pull_request) Successful in 8s
46 lines
1.7 KiB
Bash
46 lines
1.7 KiB
Bash
#!/usr/bin/env bash
|
|
# Shared helpers for validating Compose files. Sourced both by steps in
|
|
# .gitea/workflows/ci.yaml and by deploy-lib.sh on the workstation.
|
|
#
|
|
# Two levels of checking, matching how the repo is structured:
|
|
#
|
|
# general every committed Compose file, active or not. Pure structure check:
|
|
# no ${VAR} interpolation, no .env lookup, no bind-mount path
|
|
# resolution. Disabled stacks deliberately have no .env in the repo
|
|
# and no values on the CI runner, so a full `config` run would fail on
|
|
# their `${VAR:?}` guards for reasons that have nothing to do with the
|
|
# change under review.
|
|
#
|
|
# full active stacks only, with interpolation and env-file resolution, so
|
|
# required variables and referenced files are actually resolved. Needs
|
|
# the gitignored .env files, so this only runs in the deploy workflow
|
|
# on the workstation.
|
|
#
|
|
# This file is meant to be sourced, not executed.
|
|
|
|
# All committed Compose files, including the ones deploy never starts.
|
|
compose_files() {
|
|
git ls-files \
|
|
'*compose.yaml' '*compose.yml'
|
|
}
|
|
|
|
# Prints the flags that turn `docker compose config` into the general check.
|
|
# Probed rather than hardcoded so an older Compose without --no-env-resolution
|
|
# still gets the flags it does support.
|
|
compose_safe_flags() {
|
|
local help flag
|
|
help="$(docker compose config --help 2>/dev/null || true)"
|
|
for flag in --no-interpolate --no-env-resolution --no-path-resolution; do
|
|
if printf '%s' "$help" | grep -q -- "$flag"; then
|
|
printf '%s\n' "$flag"
|
|
fi
|
|
done
|
|
}
|
|
|
|
# validate_compose_file <file> [extra docker compose config flags...]
|
|
validate_compose_file() {
|
|
local file="$1"
|
|
shift
|
|
docker compose -f "$file" config --quiet "$@"
|
|
}
|