Improve workflow and generate CRDs
Some checks failed
Build and deploy / Build container and manifests (push) Failing after 5m37s

This commit is contained in:
Dreaded_X 2025-03-20 01:47:36 +01:00
parent 69588d2748
commit 5e77d8258d
Signed by: Dreaded_X
GPG Key ID: FA5F485356B0D2D4
6 changed files with 45 additions and 41 deletions

6
.dockerignore Normal file
View File

@ -0,0 +1,6 @@
.git/
.gitea/
manifests/
target/
.gitignore
.pre-commit-config.yaml

View File

@ -9,75 +9,70 @@ on:
jobs:
build:
name: Build container
name: Build container and manifests
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Login to registry
uses: docker/login-action@v3
with:
registry: git.huizinga.dev
username: ${{ gitea.actor }}
password: ${{ secrets.REGISTRY_TOKEN }}
- name: Docker meta
id: meta
uses: docker/metadata-action@v5
with:
images: git.huizinga.dev/dreaded_x/${{ gitea.event.repository.name}}
tags: |
type=edge
type=ref,event=branch
type=ref,event=pr
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=sha
type=semver,pattern=v{{version}}
type=semver,pattern=v{{major}}.{{minor}}
type=semver,pattern=v{{major}}
- name: Login to registry
uses: docker/login-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build and export to docker
id: build
uses: docker/build-push-action@v6
with:
registry: git.huizinga.dev
username: ${{ gitea.actor }}
password: ${{ secrets.REGISTRY_TOKEN }}
context: .
load: true
labels: ${{ steps.meta.outputs.labels }}
- name: Build and push Docker image
uses: https://github.com/docker/build-push-action@v5
- name: Generate CRDs
run: |
docker run --rm ${{ steps.build.outputs.imageid }} crdgen > ./manifests/crds.yaml
- name: Push container
uses: docker/build-push-action@v6
id: push
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
manifests:
name: Publish manifests
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install kustomize
run: |
curl -s "https://raw.githubusercontent.com/kubernetes-sigs/kustomize/master/hack/install_kustomize.sh" | bash
- name: Setup Flux CLI
uses: https://github.com/fluxcd/flux2/action@main
with:
version: v2.5.0
- name: Login to registry
uses: docker/login-action@v3
with:
registry: git.huizinga.dev
username: ${{ gitea.actor }}
password: ${{ secrets.REGISTRY_TOKEN }}
# TODO: Generate and include crds
- name: Generate manifets
- name: Kustomize manifests
run: |
./kustomize build ./manifests | sed "s/\${SHA_SHORT}/$(git rev-parse --short HEAD)/" > ./app.yaml
./kustomize build ./manifests | sed "s/\${DIGEST}/${{ steps.push.outputs.digest }}/" > ./manifests.yaml
- name: Push manifests
run: |
flux push artifact oci://git.huizinga.dev/dreaded_x/${{ gitea.event.repository.name }}/manifests:sha-$(git rev-parse --short HEAD) \
--path="./app.yaml" \
flux push artifact oci://git.huizinga.dev/dreaded_x/${{ gitea.event.repository.name }}/manifests:latest \
--path="./manifests.yaml" \
--source="$(git config --get remote.origin.url)" \
--revision="$(git branch --show-current)@sha1:$(git rev-parse HEAD)"
--revision="$(git branch --show-current)@sha1:$(git rev-parse HEAD)" \
$(echo ${{ steps.meta.outputs.labels }} | sed -e 's/^/-a /')
- name: Tag manifests
run: |
flux tag artifact oci://git.huizinga.dev/dreaded_x/${{ gitea.event.repository.name }}/manifests:sha-$(git rev-parse --short HEAD) \
--tag latest
$(echo ${{ steps.meta.outputs.tags }} | sed -e 's/^.*:/--tag /')

View File

@ -4,6 +4,7 @@ repos:
hooks:
- id: trailing-whitespace
- id: end-of-file-fixer
- id: check-yaml
- id: check-toml
- id: check-added-large-files
- id: check-merge-conflict

View File

@ -2,6 +2,7 @@ FROM rust:1.85 AS builder
WORKDIR /usr/src/lldap-controller
ADD . .
RUN cargo install --path .
RUN ls .
FROM debian:bookworm-slim
COPY --from=builder /usr/local/cargo/bin/lldap-controller /usr/local/bin/lldap-controller

View File

@ -21,7 +21,7 @@ spec:
securityContext: {}
containers:
- name: lldap-controller
image: git.huizinga.dev/dreaded_x/lldap-controller:sha-${SHA_SHORT}
image: git.huizinga.dev/dreaded_x/lldap-controller@${DIGEST}
imagePullPolicy: IfNotPresent
securityContext: {}
resources:

View File

@ -2,6 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: lldap
resources:
- ./crds.yaml
- ./service-account.yaml
- ./cluster-role.yaml
- ./cluster-role-binding.yaml