65 lines
2.4 KiB
YAML
65 lines
2.4 KiB
YAML
name: Validate Kubernetes & YAML
|
|
|
|
on:
|
|
push:
|
|
branches: [ "main" ]
|
|
pull_request:
|
|
branches: [ "main" ]
|
|
|
|
jobs:
|
|
validate-all:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout Code
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Install Validation Tools
|
|
run: |
|
|
# Install yamllint
|
|
sudo apt-get update && sudo apt-get install -y yamllint
|
|
|
|
# Install Helm
|
|
curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
|
|
|
# Install Kubeconform
|
|
wget https://github.com/yannh/kubeconform/releases/download/v0.6.4/kubeconform-linux-amd64.tar.gz
|
|
tar xf kubeconform-linux-amd64.tar.gz
|
|
sudo mv kubeconform /usr/local/bin/
|
|
|
|
- name: Create Yamllint Config
|
|
run: |
|
|
# We must ignore the Helm templates directory because Go templating {{ }}
|
|
# breaks standard YAML parsers.
|
|
echo -e "extends: default\nignore: |\n charts/**/templates/\n" > .yamllint.yaml
|
|
|
|
- name: Step 1 - Lint Pure YAML Files
|
|
run: yamllint .
|
|
|
|
- name: Step 2 - Lint Helm Chart Syntax
|
|
run: helm lint charts/tenant/
|
|
|
|
- name: Step 3 - Validate Static Manifests & ArgoCD CRDs
|
|
run: |
|
|
# We use a third-party CRD catalog so kubeconform understands
|
|
# ArgoCD's Application and ApplicationSet kinds in your gitops/ folder.
|
|
kubeconform -strict -summary \
|
|
-schema-location default \
|
|
-schema-location 'https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/{{.Group}}/{{.ResourceKind}}_{{.ResourceAPIVersion}}.json' \
|
|
minio/ gitops/
|
|
|
|
- name: Step 4 - Validate Tenant Configurations against Chart
|
|
run: |
|
|
# Loop through each tenant, inject their config into the Helm chart,
|
|
# and validate the resulting Kubernetes manifests.
|
|
for tenant_dir in tenants/*; do
|
|
if [ -d "$tenant_dir" ]; then
|
|
tenant_name=$(basename "$tenant_dir")
|
|
echo "------------------------------------------------"
|
|
echo "Validating rendered output for: $tenant_name"
|
|
echo "------------------------------------------------"
|
|
|
|
helm template "$tenant_name" charts/tenant/ -f "$tenant_dir/config.yaml" | \
|
|
kubeconform -strict -summary -schema-location default
|
|
fi
|
|
done
|