forked from tim/k3s-ansible
c82f2e0415
* chore(deps): apply dependency updates in one combined change - Bump ansible-core to 2.19.11 and jmespath to 1.1.0 in requirements.in - Regenerate the Python 3.11 pip-compile lock in requirements.txt - Bump molecule-plugins to 23.6.0 while keeping molecule on the stable 6.x series (avoids the molecule-plugins 26 major jump that broke vagrant module resolution in CI) - Bump ruamel-yaml-clib to 0.2.15 - Bump the zgosalvez/github-actions-ensure-sha-pinned-actions action to 5.0.6 (SHA-pinned) in lint.yml * fix(server): make log_destination conditional boolean for ansible-core 2.19 - The always block's 'Save logs of k3s-init.service' task used when: log_destination where log_destination is a path string derived from an env var - ansible-core 2.19 rejects string-derived conditionals; evaluate the path as a real boolean (non-empty) check so the conditional is a true boolean - Required to keep the k3s_server role working with ansible-core 2.19.11 (the dependency bump in this change) * fix(verify): coerce regex_search assertions to bool for ansible-core 2.19 - ansible-core 2.19 requires assert conditionals to be boolean; regex_search returns a string, which is now rejected - Wrap all regex_search results used in assert.that with | bool so the calico, cilium, metallb, and kube-vip image-tag checks produce boolean results * fix(verify): use boolean is regex_search test instead of | bool - | bool on a regex_search result coerces a tag string like v0.16.0 to False in ansible-core 2.19, failing the image-tag assertions - Use the is regex_search test which returns a real boolean without string coercion for the calico, cilium, metallb, and kube-vip image assertions * fix(verify): use is not none for regex_search assertions - ansible-core 2.19 has no "is regex_search" test and rejects bool string coercion, so use the regex_search filter with an "is not none" comparison, which yields a real boolean for the image-tag assertions - Applies to calico, cilium, metallb, and kube-vip image checks * fix(metallb): retry transient apiserver resets in config tests - The Layer 2 and BGP final configuration checks ran a kubectl get per resource with no retry, so a transient connection refused from the kube API could abort converge - Mirror the download_retries/download_delay retry pattern used by the 'Wait for MetalLB resources' task so these checks survive api server resets on slow runners
76 lines
2.5 KiB
YAML
76 lines
2.5 KiB
YAML
---
|
|
name: Linting
|
|
on:
|
|
workflow_call:
|
|
jobs:
|
|
pre-commit-ci:
|
|
name: Pre-Commit
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
PYTHON_VERSION: "3.12"
|
|
|
|
steps:
|
|
- name: Check out the codebase
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 7.0.1
|
|
with:
|
|
ref: ${{ github.event.pull_request.head.sha || github.sha }}
|
|
|
|
- name: Set up Python ${{ env.PYTHON_VERSION }}
|
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # 7.0.0
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
cache: 'pip' # caching pip dependencies
|
|
|
|
- name: Restore Ansible cache
|
|
id: cache-ansible
|
|
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # 6.1.0
|
|
with:
|
|
path: ~/.ansible/collections
|
|
key: ansible-${{ hashFiles('collections/requirements.yml') }}
|
|
|
|
- name: Install dependencies
|
|
run: |
|
|
echo "::group::Upgrade pip"
|
|
python3 -m pip install --upgrade pip
|
|
echo "::endgroup::"
|
|
|
|
echo "::group::Install Python requirements from requirements.txt"
|
|
python3 -m pip install -r requirements.txt
|
|
echo "::endgroup::"
|
|
|
|
- name: Install Ansible collections with retries
|
|
if: steps.cache-ansible.outputs.cache-hit != 'true'
|
|
run: |
|
|
set -Eeuo pipefail
|
|
for attempt in 1 2 3 4 5; do
|
|
if ansible-galaxy collection install -r collections/requirements.yml; then
|
|
exit 0
|
|
fi
|
|
echo "Ansible Galaxy attempt ${attempt} failed; retrying."
|
|
sleep $((attempt * 10))
|
|
done
|
|
exit 1
|
|
|
|
- name: Save Ansible collection cache
|
|
if: steps.cache-ansible.outputs.cache-hit != 'true'
|
|
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # 6.1.0
|
|
with:
|
|
path: ~/.ansible/collections
|
|
key: ansible-${{ hashFiles('collections/requirements.yml') }}
|
|
|
|
- name: Run pre-commit
|
|
uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd # 3.0.1
|
|
|
|
ensure-pinned-actions:
|
|
name: Ensure SHA Pinned Actions
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # 7.0.1
|
|
- name: Ensure SHA pinned actions
|
|
uses: zgosalvez/github-actions-ensure-sha-pinned-actions@46cfe808a5f1588656ef299eedd0ce2fd7ec0dcc # 5.0.6
|
|
with:
|
|
allowlist: |
|
|
aws-actions/
|
|
docker/login-action
|