Compare commits

...

7 Commits

Author SHA1 Message Date
niko 848ba723e4 Fix/git pages rentetin create tests (#46)
CI Main / Config load (push) Successful in 3m12s
CI Git-Pages Main / Config load (push) Successful in 3m4s
CI Main / Latest versio (push) Successful in 30s
CI Git-Pages Main / Latest version (push) Successful in 27s
ci-helm-build-push Helm push 0.1.9
unit-tests Bats test report
CI Main / Bats tests (push) Successful in 1m56s
CI Git-Pages Main / Build & Push Helm chart (push) Successful in 1m19s
acc-tests Cucumber test report
CI Main / Cucumber tests (push) Successful in 3m47s
ci-docker-build-push Docker push 0.2.34
CI Main / Build & Push Docker (push) Successful in 1m14s
gitops/gitea-ci-library/git-pages GitOps: git-pages 0.1.9
CI Git-Pages Main / GitOps (push) Successful in 3m37s
gitops/gitea-ci-library GitOps: 0.2.34
CI Main / GitOps (push) Successful in 40s
CI Main / Report Summary (push) Successful in 4s
CI Main / Move provider version tag (push) Successful in 12s
CI Git-Pages Main / Report Summary (push) Successful in 4s
Co-authored-by: moilanik <niko.moilanen@tietoevry.com>
Reviewed-on: #46
2026-06-26 08:07:02 +03:00
niko 1978a995a8 Update README.md (#45)
CI Main / Config load (push) Successful in 23s
CI Main / Latest versio (push) Successful in 21s
CI Main / Bats tests (push) Successful in 1m34s
CI Main / Cucumber tests (push) Successful in 1m33s
ci-docker-build-push Docker push 0.2.33
CI Main / Build & Push Docker (push) Successful in 50s
gitops/gitea-ci-library GitOps: 0.2.33
CI Main / GitOps (push) Successful in 47s
CI Main / Report Summary (push) Successful in 7s
CI Main / Move provider version tag (push) Successful in 14s
CI Feature / Load example-gitea-env.conf to pipeline env (push) Successful in 1m5s
unit-tests Bats test report
CI Feature / Bats tests (push) Successful in 2m9s
acc-tests Cucumber test report
CI Feature / Cucumber tests (push) Successful in 2m53s
CI Feature / Report Summary (push) Successful in 7s
Reviewed-on: #45
2026-06-25 09:19:01 +03:00
niko d6343438a3 Feture/gitops7 (#44)
unit-tests Bats test report
acc-tests Cucumber test report
CI Main / Cucumber tests (push) Successful in 1m44s
ci-docker-build-push Docker push 0.2.32
gitops/gitea-ci-library GitOps: 0.2.32
CI Main / Config load (push) Successful in 26s
CI Main / Latest versio (push) Successful in 21s
CI Main / Build & Push Docker (push) Has been skipped
CI Main / GitOps (push) Has been skipped
CI Main / Move provider version tag (push) Has been skipped
CI Main / Report Summary (push) Successful in 5s
CI Main / Bats tests (push) Has been skipped
Co-authored-by: moilanik <niko.moilanen@tietoevry.com>
Reviewed-on: #44
2026-06-23 12:45:42 +03:00
niko ed2703b7d7 commit status kutsujalle gitops repoon (#43)
CI Main / Config load (push) Successful in 19s
CI Main / Latest versio (push) Successful in 19s
unit-tests Bats test report
CI Main / Bats tests (push) Successful in 1m33s
acc-tests Cucumber test report
CI Main / Cucumber tests (push) Successful in 1m45s
ci-docker-build-push Docker push 0.2.31
CI Main / Build & Push Docker (push) Successful in 44s
gitops/gitea-ci-library GitOps: 0.2.31
CI Main / GitOps (push) Successful in 35s
CI Main / Report Summary (push) Successful in 7s
CI Main / Move provider version tag (push) Successful in 13s
Co-authored-by: moilanik <niko.moilanen@tietoevry.com>
Reviewed-on: #43
2026-06-22 14:24:25 +03:00
niko dc4b331ea1 kutsujalle gitops commit (#42)
CI Main / Config load (push) Successful in 26s
CI Git-Pages Main / Latest version (push) Successful in 22s
CI Git-Pages Main / Config load (push) Successful in 25s
CI Main / Latest versio (push) Successful in 21s
ci-helm-build-push Helm push 0.1.8
CI Main / Bats tests (push) Successful in 1m38s
CI Git-Pages Main / GitOps (push) Successful in 1m24s
CI Git-Pages Main / Build & Push Helm chart (push) Successful in 46s
unit-tests Bats test report
acc-tests Cucumber test report
CI Main / Cucumber tests (push) Successful in 1m59s
CI Git-Pages Main / Report Summary (push) Successful in 9s
ci-docker-build-push Docker push 0.2.30
CI Main / Build & Push Docker (push) Successful in 50s
CI Main / Move provider version tag (push) Successful in 14s
CI Main / GitOps (push) Successful in 41s
CI Main / Report Summary (push) Successful in 6s
Co-authored-by: moilanik <niko.moilanen@tietoevry.com>
Reviewed-on: #42
2026-06-22 13:57:14 +03:00
niko c06015cd9f poc logiikka takaisin (#41)
CI Main / Config load (push) Successful in 19s
CI Main / Latest versio (push) Successful in 17s
unit-tests Bats test report
CI Main / Bats tests (push) Successful in 1m30s
acc-tests Cucumber test report
CI Main / Cucumber tests (push) Successful in 1m43s
ci-docker-build-push Docker push 0.2.29
CI Main / Build & Push Docker (push) Successful in 44s
CI Main / GitOps (push) Successful in 39s
CI Main / Report Summary (push) Successful in 6s
CI Main / Move provider version tag (push) Successful in 15s
Co-authored-by: moilanik <niko.moilanen@tietoevry.com>
Reviewed-on: #41
2026-06-22 13:24:09 +03:00
niko 4c73433eab Update scripts/gitops-dispatch.sh (#40)
CI Main / Config load (push) Successful in 21s
CI Main / Latest versio (push) Successful in 19s
unit-tests Bats test report
CI Main / Bats tests (push) Successful in 1m23s
acc-tests Cucumber test report
CI Main / Cucumber tests (push) Successful in 1m43s
ci-docker-build-push Docker push 0.2.28
CI Main / Build & Push Docker (push) Successful in 33s
CI Main / GitOps (push) Failing after 18s
CI Main / Move provider version tag (push) Has been skipped
CI Main / Report Summary (push) Successful in 7s
Reviewed-on: #40
2026-06-22 11:19:56 +03:00
14 changed files with 1270 additions and 431 deletions
+140 -9
View File
@@ -22,7 +22,7 @@ on:
required: true required: true
outputs: outputs:
summary: summary:
description: 'Pipe-format: component|version|status|commit_sha|repo' description: "Pipe-format: component|version|status|commit_sha|repo"
value: ${{ jobs.dispatch.outputs.summary }} value: ${{ jobs.dispatch.outputs.summary }}
env: env:
@@ -35,24 +35,155 @@ env:
GITEA_API_URL: ${{ fromJson(inputs.env_json).GITEA_API_URL }} GITEA_API_URL: ${{ fromJson(inputs.env_json).GITEA_API_URL }}
GITOPS_TAG_PREFIX: ${{ fromJson(inputs.env_json).GIT_TAG_PREFIX || '' }} GITOPS_TAG_PREFIX: ${{ fromJson(inputs.env_json).GIT_TAG_PREFIX || '' }}
GITOPS_WORKFLOW: gitops-service.yaml GITOPS_WORKFLOW: gitops-service.yaml
GITOPS_DISPATCH_TIMEOUT: 30
jobs: jobs:
dispatch: dispatch:
runs-on: ubuntu-latest runs-on: ubuntu-latest
outputs: outputs:
summary: ${{ steps.run.outputs.GITOPS_SUMMARY }} summary: ${{ steps.summary.outputs.GITOPS_SUMMARY }}
steps: steps:
- uses: actions/checkout@v4 - name: Generate dispatch_id
id: gen
run: |
ID=$(date +%s | md5sum | head -c 8)
echo "dispatch_id=$ID" >> "$GITHUB_OUTPUT"
- name: Dispatch to GitOps repo
env:
GITEA_TOKEN: ${{ secrets.GITOPS_DISPATCH_TOKEN }}
run: |
INPUTS=$(jq -nc \
--arg dispatch_id "${{ steps.gen.outputs.dispatch_id }}" \
--arg file "$GITOPS_FILE" \
--arg yq_tpl "$GITOPS_YQ_TPL" \
--arg version "$GITOPS_VERSION" \
--arg source_repo "$GITOPS_SOURCE_REPO" \
--arg source_commit "$GITOPS_SOURCE_COMMIT" \
--arg git_tag_prefix "${GITOPS_TAG_PREFIX:-}" \
'{dispatch_id: $dispatch_id, file: $file, yq_tpl: $yq_tpl, version: $version, source_repo: $source_repo, source_commit: $source_commit, git_tag_prefix: $git_tag_prefix}')
curl -s -X POST \
"${GITEA_API_URL}/api/v1/repos/${GITOPS_REPO}/actions/workflows/${GITOPS_WORKFLOW}/dispatches" \
-H "Authorization: token $GITEA_TOKEN" \
-H "Content-Type: application/json" \
-d "$(jq -nc --arg ref "main" --argjson inputs "$INPUTS" '{ref: "main", inputs: $inputs}')"
- uses: actions/checkout@v4 - uses: actions/checkout@v4
with: with:
repository: niko/gitea-ci-library repository: niko/gitea-ci-library
path: .ci path: .ci
- name: Run gitops dispatch
id: run - name: Poll for completion
id: poll
env: env:
GITEA_TOKEN: ${{ secrets.GITOPS_DISPATCH_TOKEN }} GITEA_TOKEN: ${{ secrets.GITOPS_DISPATCH_TOKEN }}
run: | run: |
OUTPUT=$(bash .ci/scripts/gitops-dispatch.sh) ID="${{ steps.gen.outputs.dispatch_id }}"
echo "$OUTPUT" TIMEOUT_MINUTES="${GITOPS_DISPATCH_TIMEOUT:-30}"
SUMMARY=$(awk -F= '/^GITOPS_SUMMARY=/ {print $2}' <<<"$OUTPUT") POLL_INTERVAL=10
echo "GITOPS_SUMMARY=$SUMMARY" >> "$GITHUB_OUTPUT" START_TIME=$(date +%s)
TIMEOUT_SECONDS=$((TIMEOUT_MINUTES * 60))
echo "Polling for run with dispatch_id=$ID"
while [ -z "$RUN_ID" ]; do
NOW=$(date +%s)
ELAPSED=$((NOW - START_TIME))
if [ "$ELAPSED" -ge "$TIMEOUT_SECONDS" ]; then
echo "ERROR: Timeout waiting for run to appear" >&2
exit 124
fi
RUNS_RESP=$(curl -s --connect-timeout 5 --max-time 10 \
"${GITEA_API_URL}/api/v1/repos/${GITOPS_REPO}/actions/runs?event=workflow_dispatch&limit=10" \
-H "Authorization: token $GITEA_TOKEN")
RUN_ID=$(echo "$RUNS_RESP" | jq -r --arg id "$ID" \
'[.workflow_runs[] | select(.display_title | contains($id))] | .[0].id // empty')
[ -z "$RUN_ID" ] && sleep "$POLL_INTERVAL"
done
echo "Run found: id=$RUN_ID"
while true; do
NOW=$(date +%s)
ELAPSED=$((NOW - START_TIME))
if [ "$ELAPSED" -ge "$TIMEOUT_SECONDS" ]; then
echo "ERROR: Timeout waiting for completion" >&2
exit 124
fi
RUN_RESP=$(curl -s --connect-timeout 5 --max-time 10 \
"${GITEA_API_URL}/api/v1/repos/${GITOPS_REPO}/actions/runs/${RUN_ID}" \
-H "Authorization: token $GITEA_TOKEN")
STATUS=$(echo "$RUN_RESP" | jq -r '.status // "running"')
CONCLUSION=$(echo "$RUN_RESP" | jq -r '.conclusion // ""')
echo " status=$STATUS conclusion=$CONCLUSION"
if [ "$STATUS" = "completed" ]; then
if [ "$CONCLUSION" = "success" ]; then
echo "GitOps workflow completed successfully"
# 1. List recent commits from GitOps repo
COMMITS=$(curl -s --connect-timeout 5 --max-time 10 \
"${GITEA_API_URL}/api/v1/repos/${GITOPS_REPO}/commits?sha=main&limit=10" \
-H "Authorization: token $GITEA_TOKEN")
# 2. Find commit by message: "gitops: update version to X.Y.Z"
SEARCH_MSG="gitops: update version to ${GITOPS_VERSION}"
GITOPS_COMMIT=$(echo "$COMMITS" | jq -r \
--arg msg "$SEARCH_MSG" \
'[.[] | select(.commit.message | contains($msg))] | .[0].sha // empty')
# 3. If not found → fail
if [ -z "$GITOPS_COMMIT" ]; then
echo "ERROR: no matching GitOps commit found for version ${GITOPS_VERSION}" >&2
exit 1
fi
echo "GITOPS_COMMIT=$GITOPS_COMMIT" >> "$GITHUB_OUTPUT"
echo "$GITOPS_COMMIT" > /tmp/gitops-commit
exit 0
else
echo "ERROR: GitOps workflow failed with conclusion=$CONCLUSION" >&2
exit 1
fi
fi
sleep "$POLL_INTERVAL"
done
- name: GitOps summary
id: summary
if: always()
run: |
STATUS="failure"
GITOPS_SHA=""
if [ -f /tmp/gitops-commit ]; then
STATUS="success"
GITOPS_SHA=$(cat /tmp/gitops-commit)
fi
COMPONENT="${GITOPS_TAG_PREFIX:-${GITOPS_FILE}}"
echo "GITOPS_SUMMARY=${COMPONENT}|${GITOPS_VERSION}|${STATUS}|${GITOPS_SHA}|${GITOPS_REPO}" >> "$GITHUB_OUTPUT"
- name: Set commit status
if: success()
env:
GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
GITOPS_SHA=$(cat /tmp/gitops-commit)
PREFIX="${GITOPS_TAG_PREFIX%/}"
if [ -n "$PREFIX" ]; then
CONTEXT="gitops/$(basename "${GITOPS_SOURCE_REPO}")/${PREFIX}"
DESCRIPTION="GitOps: ${PREFIX} ${GITOPS_VERSION}"
else
CONTEXT="gitops/$(basename "${GITOPS_SOURCE_REPO}")"
DESCRIPTION="GitOps: ${GITOPS_VERSION}"
fi
ROOT_REPO="${GITOPS_SOURCE_REPO}" ROOT_COMMIT="${GITOPS_SOURCE_COMMIT}" \
bash .ci/scripts/report-status.sh success \
"$DESCRIPTION" "$CONTEXT" "" \
"${GITEA_API_URL}/${GITOPS_REPO}/commit/${GITOPS_SHA}"
+13
View File
@@ -8,6 +8,12 @@ on:
version: version:
required: true required: true
type: string type: string
chart_path:
required: true
type: string
extra_dependency_paths:
required: false
type: string
secrets: secrets:
GITEA_TOKEN: GITEA_TOKEN:
required: true required: true
@@ -47,6 +53,13 @@ jobs:
repository: niko/gitea-ci-library repository: niko/gitea-ci-library
path: .ci path: .ci
- name: Resolve extra subchart dependencies
if: inputs.extra_dependency_paths != ''
run: |
for path in $(echo "${{ inputs.extra_dependency_paths }}" | tr ',' '\n'); do
helm dependency update "${path}"
done
- name: Package Helm chart - name: Package Helm chart
run: | run: |
CHART_DIR=$(dirname "${CHART_FILE}") CHART_DIR=$(dirname "${CHART_FILE}")
+1
View File
@@ -280,3 +280,4 @@ Tarkka asennus: [skills/gitops-update/SKILL.md](skills/gitops-update/SKILL.md)
| `existingSecretKey` | Avain secretin sisällä | | `existingSecretKey` | Avain secretin sisällä |
| `statefulset.dind.tag` | DinD-image tag (`29.5.2-dind` minimi) | | `statefulset.dind.tag` | DinD-image tag (`29.5.2-dind` minimi) |
| `statefulset.runner.labels` | Mukautetut labelit | | `statefulset.runner.labels` | Mukautetut labelit |
+6 -4
View File
@@ -103,7 +103,8 @@ joten `actions/checkout` toimii ilman node-asennuksia.
|-----------|------------|--------| |-----------|------------|--------|
| `env_json` | Kyllä | Konffi `gitea-env.conf`:stä | | `env_json` | Kyllä | Konffi `gitea-env.conf`:stä |
| `version` | Kyllä | Version string (check-version output) | | `version` | Kyllä | Version string (check-version output) |
| `chart_path` | Ei | Polku Chart.yaml-hakemistoon, oletus `.` | | `chart_path` | Kyllä | Polku Chart.yaml-hakemistoon |
| `extra_dependency_paths` | Ei | Pilkulla erotellut polut subcharttien dependeinceille, joille ajetaan `helm dependency update` ennen päächartin buildia |
**`env_json`-avaimet:** **`env_json`-avaimet:**
@@ -124,9 +125,10 @@ build-push (helm package → helm push OCI) → tag-commit (git-tagin luonti)
**Steppien kuvaus `build-push`-jobissa:** **Steppien kuvaus `build-push`-jobissa:**
1. **Node.js-asennus**`apk add --no-cache nodejs` (vaaditaan `actions/checkout`-actionia varten) 1. **Node.js-asennus**`apk add --no-cache nodejs` (vaaditaan `actions/checkout`-actionia varten)
2. **Checkout** — sovellusrepo ja gitea-ci-library `.ci/`-polkuun 2. **Checkout** — sovellusrepo ja gitea-ci-library `.ci/`-polkuun
3. **Package**`helm package` versiolla `$VERSION` 3. **Resolve extra subchart dependencies**`helm dependency update` jokaiselle `extra_dependency_paths`-polulle (vain jos input on annettu)
4. **Push OCI**`helm push` registryyn autentikoinnilla 4. **Package**`helm dependency update` + `helm package` versiolla `$VERSION`
5. **Report status** — commit-status + UI-linkki 5. **Push OCI**`helm push` registryyn autentikoinnilla
6. **Report status** — commit-status + UI-linkki
**Kompromissi:** Kontti `alpine/helm` ei sisällä node.js:ää, mutta **Kompromissi:** Kontti `alpine/helm` ei sisällä node.js:ää, mutta
`actions/checkout@v4` on JavaScript-action ja vaatii sen. Siksi nodejs `actions/checkout@v4` on JavaScript-action ja vaatii sen. Siksi nodejs
+40 -1
View File
@@ -122,7 +122,7 @@ helm upgrade --install git-pages ./git-pages \
helm template git-pages ./git-pages -f "$VALUES" helm template git-pages ./git-pages -f "$VALUES"
``` ```
--- ---
## CI-julkaisu ## CI-julkaisu
@@ -149,3 +149,42 @@ curl -X PATCH https://ci-reports.helm-dev.keskikuja.site/owner/repo/commit/sha8/
- `git-pages-publish-token` = plaintext (luetaan Giteaan viedessä) - `git-pages-publish-token` = plaintext (luetaan Giteaan viedessä)
Tarkemmat secret-ohjeet: [docs/secrets.md](docs/secrets.md). Tarkemmat secret-ohjeet: [docs/secrets.md](docs/secrets.md).
---
## Testaus
Retention-logiikalle on unit-testit, jotka testaa funktiot ja Phase 3 -säännöt
erikseen ilman ulkoisia riippuvuuksia.
```bash
cd git-pages
bats tests/retention.bats
```
Testit käyttävät `<root>/files/retention-lib.sh` -jaettua kirjastoa, jota myös
`retention-cleanup.sh` sourceaa. Uutta testiä kirjoittaessa:
1. Luo config `write_config`-helperilla
2. Täytä `KEEP`-array testidatalla (muoto: `dir|owner|repo|branch|days`)
3. Kutsu `apply_retention "$CONFIG"`
4. Tarkista `TO_DELETE`-array ja `$output`
**Vaatimukset:** `bats`, `jq`, `date` (GNU date tai BSD date ISO 8601 -tuella).
---
## Retention
Ylläpitoscripti, joka poistaa vanhat raportit git-pagesista retentionsääntöjen mukaan.
Ajetaan sidecar tai cronjobtilassa Kubernetesissa.
### Air gap -yhteensopimattomuus
Retentionkontti asentaa tarvitsemansa työkalut (`curl`, `jq`) ajon aikana
packagemanagerilla (`apt-get` / `apk`). Tämä **ei toimi air gap -ympäristössä**,
jossa konttirekisteriin tai pakettivarastoihin ei ole verkkoyhteyttä.
**TODO:** Rakenna custom Dockerimage, jossa deps on valmiina:
`FROM alpine:latest && apk add --no-cache curl jq`.
Pushaa omaan rekisteriin ja päivitä `values.yaml`:n `retention.image`.
+117 -106
View File
@@ -13,75 +13,11 @@ curl_with_host() {
[ -f "$CONFIG" ] || { echo "ERROR: config missing: $CONFIG" >&2; exit 1; } [ -f "$CONFIG" ] || { echo "ERROR: config missing: $CONFIG" >&2; exit 1; }
declare -A BRANCH_CACHE declare -A REPO_BRANCHES_CACHE
branch_exists() { declare -A REPO_STATUS
local owner="$1" repo="$2" branch="$3" key="${owner}/${repo}/${branch}"
local status attempt
[ -z "$GITEA_API_URL" ] && return 0
[ -z "$GITEA_TOKEN" ] && return 0
if [ "${BRANCH_CACHE[$key]:-}" = "1" ]; then
return 0
fi
# Retry up to 2 times on API errors (hardcoded)
for attempt in 1 2 3; do
status=$(curl -sS -o /dev/null -w "%{http_code}" \
-H "Authorization: token ${GITEA_TOKEN}" \
"${GITEA_API_URL}/api/v1/repos/${owner}/${repo}/branches/${branch}" 2>/dev/null || echo "000")
if [ "$status" = "200" ]; then
BRANCH_CACHE[$key]=1
return 0
fi
if [ "$status" = "404" ]; then
return 1
fi
# API error - retry if not last attempt
if [ "$attempt" -lt 3 ]; then
sleep 10
continue
fi
done
# All retries failed - keep report (fail-safe)
echo " WARN: Gitea API error for ${owner}/${repo}/${branch} (status ${status}) after 3 attempts - KEEPING report"
BRANCH_CACHE[$key]=1
return 0
}
default_max_age=$(jq -r '.branches.default.maxAgeDays // 90' "$CONFIG") SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
default_keep_min=$(jq -r '.branches.default.keepMin // 5' "$CONFIG") source "$SCRIPT_DIR/retention-lib.sh"
rule_max_age() {
local branch="$1" v
v=$(jq -r --arg b "$branch" '.branches[$b].maxAgeDays // empty' "$CONFIG")
[ -n "$v" ] && echo "$v" || echo "$default_max_age"
}
rule_keep_min() {
local branch="$1" v
v=$(jq -r --arg b "$branch" '.branches[$b].keepMin // empty' "$CONFIG")
[ -n "$v" ] && echo "$v" || echo "$default_keep_min"
}
age_days() {
local published="$1" epoch_pub now
epoch_pub=$(date -u -d "$published" +%s 2>/dev/null || echo 0)
[ "$epoch_pub" -eq 0 ] && echo 99999 && return
now=$(date -u +%s)
echo $(( (now - epoch_pub) / 86400 ))
}
parse_path() {
local rel="$1"
OWNER="${rel%%/*}"
rest="${rel#*/}"
REPO="${rest%%/*}"
}
echo "Fetching manifest from ${PAGES_URL}/.git-pages/manifest.json" echo "Fetching manifest from ${PAGES_URL}/.git-pages/manifest.json"
MANIFEST=$(curl_with_host "${PAGES_URL}/.git-pages/manifest.json") MANIFEST=$(curl_with_host "${PAGES_URL}/.git-pages/manifest.json")
@@ -97,6 +33,7 @@ fi
echo "" echo ""
echo "=== Phase 1: collect reports ===" echo "=== Phase 1: collect reports ==="
declare -A SEEN_REPORTS declare -A SEEN_REPORTS
declare -A SEEN_ECHO_COMMITS
declare -a REPORTS declare -a REPORTS
while IFS= read -r meta_path; do while IFS= read -r meta_path; do
report_dir=$(dirname "$meta_path") report_dir=$(dirname "$meta_path")
@@ -117,58 +54,105 @@ while IFS= read -r meta_path; do
days=$(age_days "$published") days=$(age_days "$published")
REPORTS+=("${report_dir}|${OWNER}|${REPO}|${branch}|${days}") REPORTS+=("${report_dir}|${OWNER}|${REPO}|${branch}|${days}")
echo " ${OWNER}/${REPO} branch=${branch} age=${days}d"
commit_dir=$(dirname "$report_dir")
if [ -z "${SEEN_ECHO_COMMITS[$commit_dir]:-}" ]; then
SEEN_ECHO_COMMITS[$commit_dir]=1
echo " ${commit_dir} branch=${branch} age=${days}d"
fi
done <<< "$META_PATHS" done <<< "$META_PATHS"
[ "${#REPORTS[@]}" -eq 0 ] && { echo "No actionable reports"; exit 0; } [ "${#REPORTS[@]}" -eq 0 ] && { echo "No actionable reports"; exit 0; }
echo "" echo ""
echo "=== Phase 2: check branches in Gitea ===" echo "=== Phase 2: check branches/repos in Gitea ==="
if [ -z "$GITEA_API_URL" ] || [ -z "$GITEA_TOKEN" ]; then
echo "ERROR: GITEA_API_URL and GITEA_TOKEN must be set" >&2
exit 1
fi
declare -a TO_DELETE declare -a TO_DELETE
declare -a KEEP declare -a KEEP
declare -A SEEN_ECHO_BRANCHES
declare -A SEEN_ECHO_REPO_DELETED
declare -A UNIQUE_BRANCHES
declare -A REASON_MAP
declare -A COMMIT_BRANCH_MAP
# Build commit→branch mapping
for entry in "${REPORTS[@]}"; do
IFS='|' read -r dir _ _ branch _ <<< "$entry"
commit_dir=$(dirname "$dir")
[ -n "${COMMIT_BRANCH_MAP[$commit_dir]:-}" ] || COMMIT_BRANCH_MAP["$commit_dir"]=$branch
done
for entry in "${REPORTS[@]}"; do
IFS='|' read -r _ owner repo branch _ <<< "$entry"
UNIQUE_BRANCHES["${owner}/${repo}/${branch}"]=1
done
TOTAL_BRANCHES=${#UNIQUE_BRANCHES[@]}
BRANCHES_EXISTING=0
BRANCH_DELETED_COUNT=0
REPO_DELETED_COUNT=0
MAXAGE_DELETED=0
KEEPMIN_DELETED=0
for entry in "${REPORTS[@]}"; do for entry in "${REPORTS[@]}"; do
IFS='|' read -r dir owner repo branch days <<< "$entry" IFS='|' read -r dir owner repo branch days <<< "$entry"
if [ -n "$GITEA_API_URL" ] && [ -n "$GITEA_TOKEN" ]; then branch_key="${owner}/${repo}/${branch}"
if branch_exists "$owner" "$repo" "$branch"; then if branch_exists "$owner" "$repo" "$branch"; then
echo " BRANCH EXISTS: ${owner}/${repo}/${branch}" if [ -z "${SEEN_ECHO_BRANCHES[$branch_key]:-}" ]; then
KEEP+=("${dir}|${owner}|${repo}|${branch}|${days}") SEEN_ECHO_BRANCHES[$branch_key]=1
else BRANCHES_EXISTING=$((BRANCHES_EXISTING + 1))
echo " BRANCH DELETED: ${owner}/${repo}/${branch} -> DELETE" echo " BRANCH EXISTS: ${branch_key}"
TO_DELETE+=("$dir")
fi fi
else
KEEP+=("${dir}|${owner}|${repo}|${branch}|${days}") KEEP+=("${dir}|${owner}|${repo}|${branch}|${days}")
else
if [ -z "${SEEN_ECHO_BRANCHES[$branch_key]:-}" ]; then
SEEN_ECHO_BRANCHES[$branch_key]=1
repo_key="${owner}/${repo}"
if [ "${REPO_STATUS[$repo_key]:-}" = "deleted" ]; then
REPO_DELETED_COUNT=$((REPO_DELETED_COUNT + 1))
if [ -z "${SEEN_ECHO_REPO_DELETED[$repo_key]:-}" ]; then
SEEN_ECHO_REPO_DELETED[$repo_key]=1
echo " REPO DELETED: ${repo_key} -> DELETE ALL"
fi
reason="repo deleted"
else
BRANCH_DELETED_COUNT=$((BRANCH_DELETED_COUNT + 1))
echo " BRANCH DELETED: ${branch_key} -> DELETE"
reason="branch deleted"
fi
fi
REASON_MAP["$dir"]="$reason"
TO_DELETE+=("$dir")
fi fi
done done
echo "" echo ""
echo "=== Phase 3: apply retention rules to remaining reports ===" echo "=== Phase 3: apply retention rules to remaining reports ==="
declare -A BRANCH_COUNTS PHASE2_DELETED=${#TO_DELETE[@]}
if [ "${#KEEP[@]}" -gt 0 ]; then apply_retention "$CONFIG"
IFS=$'\n' PHASE3_DELETED=$(( ${#TO_DELETE[@]} - PHASE2_DELETED ))
for entry in $(printf '%s\n' "${KEEP[@]}" | sort -t'|' -k4,4 -k5,5rn); do
IFS='|' read -r dir owner repo branch days <<< "$entry"
max_age=$(rule_max_age "$branch")
keep_min=$(rule_keep_min "$branch")
if [ "$days" -gt "$max_age" ]; then fmt_num() {
echo " DELETE: ${dir} (age ${days}d > maxAge ${max_age}d, branch ${branch})" local n="$1" out=""
TO_DELETE+=("$dir") [ -z "$n" ] && { echo "?"; return; }
continue n="${n##0}" # strip leading zeros
fi while [ "${#n}" -gt 3 ]; do
out=" ${n: -3}$out"
key="${branch}" n="${n:0:${#n}-3}"
count="${BRANCH_COUNTS[$key]:-0}"
count=$((count + 1))
BRANCH_COUNTS["$key"]=$count
if [ "$count" -gt "$keep_min" ]; then
echo " DELETE: ${dir} (kept ${keep_min}/${count}, exceeds keepMin, branch ${branch})"
TO_DELETE+=("$dir")
fi
done done
unset IFS echo "${n}${out}"
fi }
echo ""
echo "=== Summary ==="
echo " Branches:"
echo " existing: $(fmt_num $BRANCHES_EXISTING)"
echo " deleted: $(fmt_num $BRANCH_DELETED_COUNT)"
echo " repo gone: $(fmt_num $REPO_DELETED_COUNT)"
echo " Commits:"
echo " deleted by maxAge: $(fmt_num $MAXAGE_DELETED)"
echo " deleted by keepMin:$(fmt_num $KEEPMIN_DELETED)"
if [ "${#TO_DELETE[@]}" -eq 0 ]; then if [ "${#TO_DELETE[@]}" -eq 0 ]; then
echo "Nothing to delete" echo "Nothing to delete"
@@ -193,14 +177,37 @@ echo "Downloading archive.tar..."
HTTP_CODE=$(curl_with_host -o "$ARCHIVE_FILE" -w "%{http_code}" -sS "${PAGES_URL}/.git-pages/archive.tar") HTTP_CODE=$(curl_with_host -o "$ARCHIVE_FILE" -w "%{http_code}" -sS "${PAGES_URL}/.git-pages/archive.tar")
if [ "$HTTP_CODE" = "200" ] && tar -tf "$ARCHIVE_FILE" >/dev/null 2>&1; then if [ "$HTTP_CODE" = "200" ] && tar -tf "$ARCHIVE_FILE" >/dev/null 2>&1; then
echo "Extracting archive..." OLD_KB=$(du -sk "$ARCHIVE_FILE" 2>/dev/null | awk '{print $1}')
echo "Extracting archive (${OLD_KB}kB)..."
tar -xf "$ARCHIVE_FILE" -C "$SITE_DIR" tar -xf "$ARCHIVE_FILE" -C "$SITE_DIR"
for dir in "${TO_DELETE[@]}"; do declare -A GROUP_SEEN
if [ -d "$SITE_DIR/$dir" ]; then declare -A GROUP_LINES
echo " Removing: $dir" for del in "${TO_DELETE[@]}"; do
rm -rf "$SITE_DIR/$dir" if [ ! -d "$SITE_DIR/$del" ]; then
continue
fi fi
commit_dir=$(dirname "$del")
branch="${COMMIT_BRANCH_MAP[$commit_dir]:-?}"
reason="${REASON_MAP[$del]:-?}"
repo_path="${del%%/reports/*}"
commit_hash="${commit_dir##*/}"
key="${repo_path}/${branch} | Reason: ${reason}"
seen_key="${key}|${commit_hash}"
if [ -z "${GROUP_SEEN[$seen_key]:-}" ]; then
GROUP_SEEN[$seen_key]=1
GROUP_LINES["$key"]="${GROUP_LINES[$key]:-} $commit_hash"
fi
rm -rf "$SITE_DIR/$del"
done
for key in "${!GROUP_LINES[@]}"; do
echo " Removing: ${key}"
for hash in ${GROUP_LINES[$key]}; do
echo " commit: ${hash}"
done
done done
else else
echo "archive.tar failed (HTTP ${HTTP_CODE}) - falling back to manifest-based rebuild" echo "archive.tar failed (HTTP ${HTTP_CODE}) - falling back to manifest-based rebuild"
@@ -248,6 +255,7 @@ if [ -z "$(ls -A "$SITE_DIR" 2>/dev/null)" ]; then
fi fi
tar -cf "$NEW_TAR" -C "$SITE_DIR" . tar -cf "$NEW_TAR" -C "$SITE_DIR" .
NEW_KB=$(du -sk "$NEW_TAR" 2>/dev/null | awk '{print $1}')
echo "PUT: replacing site contents..." echo "PUT: replacing site contents..."
HTTP_CODE=$(curl_with_host -X PUT "${PAGES_URL}/" \ HTTP_CODE=$(curl_with_host -X PUT "${PAGES_URL}/" \
@@ -259,6 +267,9 @@ HTTP_CODE=$(curl_with_host -X PUT "${PAGES_URL}/" \
echo "HTTP ${HTTP_CODE}" echo "HTTP ${HTTP_CODE}"
if [ "$HTTP_CODE" = "200" ] || [ "$HTTP_CODE" = "201" ] || [ "$HTTP_CODE" = "204" ]; then if [ "$HTTP_CODE" = "200" ] || [ "$HTTP_CODE" = "201" ] || [ "$HTTP_CODE" = "204" ]; then
echo "Site rebuild completed." echo "Site rebuild completed."
if [ -n "${OLD_KB:-}" ]; then
echo " archive size: $(fmt_num $OLD_KB)kB → $(fmt_num $NEW_KB)kB"
fi
else else
echo "ERROR: PUT HTTP ${HTTP_CODE}" >&2 echo "ERROR: PUT HTTP ${HTTP_CODE}" >&2
exit 1 exit 1
+184
View File
@@ -0,0 +1,184 @@
#!/usr/bin/env bash
# Shared functions for retention-cleanup.sh
# Can be sourced by tests for unit testing
age_days() {
local published="$1" epoch_pub now
epoch_pub=$(date -d "$published" +%s 2>/dev/null || date -j -f "%Y-%m-%dT%H:%M:%SZ" "$published" +%s 2>/dev/null || echo 0)
[ "$epoch_pub" -eq 0 ] && echo 99999 && return
now=$(date -u +%s)
echo $(( (now - epoch_pub) / 86400 ))
}
parse_path() {
local rel="$1"
OWNER="${rel%%/*}"
rest="${rel#*/}"
REPO="${rest%%/*}"
}
read_rule() {
local config="$1" branch="$2" key="$3" default="$4"
v=$(jq -r --arg b "$branch" --arg k "$key" '.branches[$b][$k] // empty' "$config")
[ -n "$v" ] && echo "$v" || echo "$default"
}
# ---------------------------------------------------------------------------
# Gitea branch/repo checking via git ls-remote
# Uses global: GITEA_API_URL, GITEA_TOKEN
# Sets global: REPO_BRANCHES_CACHE, REPO_STATUS
# ---------------------------------------------------------------------------
# Fetch all branches for a repo (one git ls-remote call per repo).
# Sets REPO_STATUS[owner/repo].
# Echos branch list on success.
# Returns: 0=ok, 1=deleted, 2=cert_error, 3=error (fail-safe keep)
repo_branches() {
local owner="$1" repo="$2" key="${owner}/${repo}"
local attempt output
[ -z "$GITEA_API_URL" ] && return 0
[ -z "$GITEA_TOKEN" ] && return 0
# Check cached status first (avoids re-running git on every report)
case "${REPO_STATUS[$key]:-}" in
deleted) return 1 ;;
cert_error) return 2 ;;
error) echo "${REPO_BRANCHES_CACHE[$key]:-}"; return 3 ;;
esac
# Cache hit (success with branch list)
[ -n "${REPO_BRANCHES_CACHE[$key]:-}" ] && { echo "${REPO_BRANCHES_CACHE[$key]}"; return 0; }
local git_host
git_host=$(echo "$GITEA_API_URL" | sed -E 's|^https?://||' | sed 's|/.*$||')
local git_url="https://token:${GITEA_TOKEN}@${git_host}/${owner}/${repo}.git"
for attempt in 1 2 3; do
output=$(git ls-remote --heads "$git_url" 2>&1) && {
local branches
branches=$(echo "$output" | sed -n 's|.*refs/heads/||p')
REPO_BRANCHES_CACHE[$key]="$branches"
REPO_STATUS[$key]="ok"
echo "$branches"
return 0
}
# Repo deleted → no retry
if echo "$output" | grep -qiE "fatal:.*(not found|repository.*not|could not read)"; then
REPO_BRANCHES_CACHE[$key]="__REPO_DELETED__"
REPO_STATUS[$key]="deleted"
echo " REPO DELETED: ${owner}/${repo}" >&2
return 1
fi
[ "$attempt" -lt 3 ] && sleep 10
done
# Certificate verification failure → configuration error, stop
if echo "$output" | grep -qi "server certificate verification failed"; then
REPO_STATUS[$key]="cert_error"
echo "[ERROR] git-pages.retention: certificate verification failed for ${owner}/${repo}" >&2
echo "[ERROR] git-pages.retention: check CA certificates or set GIT_SSL_NO_VERIFY=1" >&2
echo "[ERROR] git-pages.retention: git output:" >&2
echo "$output" >&2
return 2
fi
# Other network errors → fail-safe keep, continue
REPO_BRANCHES_CACHE[$key]="__REPO_ERROR__"
REPO_STATUS[$key]="error"
echo "[WARN] git-pages.retention: cannot reach Gitea for ${owner}/${repo} — keeping all reports" >&2
echo "[WARN] git-pages.retention: git output:" >&2
echo "$output" >&2
return 3
}
# Check if a specific branch exists in a repo.
# Returns 0 (exists), 1 (not found/deleted).
# Returns 2 (cert error), 3 (network error).
branch_exists() {
local owner="$1" repo="$2" branch="$3"
local branches rc
[ -z "$GITEA_API_URL" ] && return 0
[ -z "$GITEA_TOKEN" ] && return 0
branches=$(repo_branches "$owner" "$repo")
rc=$?
# Return codes from repo_branches propagate through $() subshell:
# 0=ok, 1=deleted, 2=cert_error, 3=error
case $rc in
2) echo "[FATAL] git-pages.retention: cannot reach Gitea (${owner}/${repo}) — check configuration" >&2
exit 1 ;;
3) return 0 ;; # network error → fail-safe keep
1) return 1 ;; # repo/branch gone
esac
echo "$branches" | grep -qxF "$branch"
}
# Phase 3: apply retention rules to KEEP array, populate TO_DELETE
# Reads from global KEEP array
# Populates global TO_DELETE array
# Usage: apply_retention <config_path>
apply_retention() {
local config="$1"
local default_max_age default_keep_min
local max_age keep_min key count seen_key commit_dir
local entry dir owner repo branch days
default_max_age=$(jq -r '.branches.default.maxAgeDays // 90' "$config")
default_keep_min=$(jq -r '.branches.default.keepMin // 5' "$config")
declare -A BRANCH_COUNTS
declare -A SEEN_COMMITS
declare -A DELETED_COMMITS
if [ "${#KEEP[@]}" -eq 0 ]; then
return
fi
IFS=$'\n'
for entry in $(printf '%s\n' "${KEEP[@]}" | sort -t'|' -k4,4 -k5,5n); do
IFS='|' read -r dir owner repo branch days <<< "$entry"
max_age=$(read_rule "$config" "$branch" "maxAgeDays" "$default_max_age")
keep_min=$(read_rule "$config" "$branch" "keepMin" "$default_keep_min")
# Age check — per-report-type deletion
if [ "$days" -gt "$max_age" ]; then
echo " DELETE: ${dir} (age ${days}d > maxAge ${max_age}d, branch ${branch})"
TO_DELETE+=("$dir")
REASON_MAP["$dir"]="maxAgeDays exceed"
MAXAGE_DELETED=$((MAXAGE_DELETED + 1))
continue
fi
# keepMin — per-commit counting
commit_dir=$(dirname "$dir")
key="$branch"
seen_key="${key}|${commit_dir}"
if [ -z "${SEEN_COMMITS[$seen_key]:-}" ]; then
SEEN_COMMITS["$seen_key"]=1
count="${BRANCH_COUNTS[$key]:-0}"
count=$((count + 1))
BRANCH_COUNTS["$key"]=$count
else
count="${BRANCH_COUNTS[$key]:-0}"
fi
if [ "$count" -gt "$keep_min" ]; then
if [ -z "${DELETED_COMMITS[$commit_dir]:-}" ]; then
DELETED_COMMITS[$commit_dir]=1
echo " DELETE: ${commit_dir} (kept ${keep_min}/${count} commits, exceeds keepMin, branch ${branch})"
TO_DELETE+=("$commit_dir")
REASON_MAP["$commit_dir"]="keepMin exceed"
KEEPMIN_DELETED=$((KEEPMIN_DELETED + 1))
fi
fi
done
unset IFS
}
+8 -1
View File
@@ -70,8 +70,15 @@ spec:
set -euo pipefail set -euo pipefail
echo "Retention sidecar: installing deps..." echo "Retention sidecar: installing deps..."
apt-get update -qq apt-get update -qq
apt-get install -y --no-install-recommends curl jq python3 >/dev/null apt-get install -y --no-install-recommends curl jq git ca-certificates >/dev/null
echo "Retention sidecar: ready" echo "Retention sidecar: ready"
# Sleep until 01:00 so retention runs at night
now_epoch=$(date +%s)
target_epoch=$(date -d "today 01:00:00" +%s)
[ "$target_epoch" -le "$now_epoch" ] && target_epoch=$((target_epoch + 86400))
sleep_sec=$((target_epoch - now_epoch))
echo "Retention sidecar: next run in $((sleep_sec / 3600))h (at 01:00)"
sleep $sleep_sec
while true; do while true; do
/scripts/retention-cleanup.sh /scripts/retention-cleanup.sh
echo "Retention sidecar: next run in 24h" echo "Retention sidecar: next run in 24h"
@@ -8,6 +8,8 @@ metadata:
data: data:
retention.json: | retention.json: |
{{- .Values.retention.rules | toJson | nindent 4 }} {{- .Values.retention.rules | toJson | nindent 4 }}
retention-lib.sh: |
{{- .Files.Get "files/retention-lib.sh" | nindent 4 }}
retention-cleanup.sh: | retention-cleanup.sh: |
{{- .Files.Get "files/retention-cleanup.sh" | nindent 4 }} {{- .Files.Get "files/retention-cleanup.sh" | nindent 4 }}
retention-run.sh: | retention-run.sh: |
+1 -1
View File
@@ -33,7 +33,7 @@ spec:
- | - |
set -euo pipefail set -euo pipefail
apt-get update -qq apt-get update -qq
apt-get install -y --no-install-recommends curl jq >/dev/null apt-get install -y --no-install-recommends curl jq git >/dev/null
chmod +x /scripts/retention-run.sh /scripts/retention-cleanup.sh chmod +x /scripts/retention-run.sh /scripts/retention-cleanup.sh
/scripts/retention-run.sh /scripts/retention-run.sh
env: env:
+623
View File
@@ -0,0 +1,623 @@
#!/usr/bin/env bats
setup() {
source "$(dirname "$BATS_TEST_DIRNAME")/files/retention-lib.sh"
declare -gA REPO_BRANCHES_CACHE
declare -gA REPO_STATUS
declare -gA REASON_MAP
MAXAGE_DELETED=0
KEEPMIN_DELETED=0
CONFIG=$(mktemp)
}
teardown() {
rm -f "$CONFIG"
}
write_config() {
cat > "$CONFIG"
}
# ---------------------------------------------------------------------------
# read_rule
# ---------------------------------------------------------------------------
@test "read_rule returns default when branch has no override" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5}}}
EOF
result=$(read_rule "$CONFIG" "nonexistent" "maxAgeDays" 90)
[ "$result" = "90" ]
}
@test "read_rule returns branch-specific value" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5},"main":{"maxAgeDays":365,"keepMin":20}}}
EOF
result=$(read_rule "$CONFIG" "main" "keepMin" 5)
[ "$result" = "20" ]
}
@test "read_rule returns default for undefined key even if branch exists" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5},"main":{"maxAgeDays":365}}}
EOF
result=$(read_rule "$CONFIG" "main" "keepMin" 5)
[ "$result" = "5" ]
}
# ---------------------------------------------------------------------------
# parse_path
# ---------------------------------------------------------------------------
@test "parse_path extracts owner and repo" {
parse_path "my-owner/my-repo/reports/abc123/go-test-unit"
[ "$OWNER" = "my-owner" ]
[ "$REPO" = "my-repo" ]
}
@test "parse_path handles owner with hyphens" {
parse_path "niko/agent-platform/reports/abc1234/go-test-bdd"
[ "$OWNER" = "niko" ]
[ "$REPO" = "agent-platform" ]
}
# ---------------------------------------------------------------------------
# apply_retention — keepMin per commit
# ---------------------------------------------------------------------------
@test "keepMin: 6 commits × 4 types, keepMin=10 → all kept (6 commits < 10)" {
# With old per-file counting, 24 files > 10 keepMin would delete 14.
# With per-commit counting, 6 commits < 10 keepMin keeps everything.
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":10}}}
EOF
KEEP=()
local -a commits=(c1 c2 c3 c4 c5 c6)
local -a ages=(100 80 60 40 20 5)
local -a types=(go-test-bdd go-test-unit helm-lint helm-kubeconform)
for i in "${!commits[@]}"; do
for t in "${types[@]}"; do
KEEP+=("niko/agent-platform/reports/${commits[$i]}/$t|niko|agent-platform|main|${ages[$i]}")
done
done
TO_DELETE=()
apply_retention "$CONFIG"
[ "${#TO_DELETE[@]}" -eq 0 ]
}
@test "keepMin: 8 commits × 1 type, keepMin=5 → deletes 3 oldest" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":5}}}
EOF
KEEP=()
local -a ages=(80 70 60 50 40 30 20 10)
for i in "${!ages[@]}"; do
KEEP+=("niko/r/reports/c$((i+1))/test|niko|r|main|${ages[$i]}")
done
TO_DELETE=()
apply_retention "$CONFIG"
# 5 newest (c8-c4) kept, 3 oldest (c3,c2,c1) deleted
[ "${#TO_DELETE[@]}" -eq 3 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/c3" ]]
[[ "${TO_DELETE[1]}" == "niko/r/reports/c2" ]]
[[ "${TO_DELETE[2]}" == "niko/r/reports/c1" ]]
}
@test "keepMin: 12 commits × 1 type, keepMin=5 → keeps 5 newest, deletes 7 oldest" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5}}}
EOF
KEEP=()
for i in $(seq 1 12); do
KEEP+=("niko/r/reports/c${i}/test|niko|r|feature/foo|$(( 13 - i ))")
done
TO_DELETE=()
apply_retention "$CONFIG"
# 7 oldest commits deleted (12 - 5 = 7)
[ "${#TO_DELETE[@]}" -eq 7 ]
# Oldest 7 should be c1..c7 (highest days = oldest = processed last after sort)
# Sort is ascending by days, so processed as c12(1d), c11(2d), ..., c1(12d)
# keepMin=5: c12-c8 kept, c7-c1 deleted
[[ "${TO_DELETE[0]}" == "niko/r/reports/c7" ]]
[[ "${TO_DELETE[6]}" == "niko/r/reports/c1" ]]
}
@test "keepMin: 2 commits × 3 types, keepMin=5 → all kept (2 < 5)" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5}}}
EOF
KEEP=()
KEEP+=("niko/r/reports/c1/test-a|niko|r|main|30")
KEEP+=("niko/r/reports/c1/test-b|niko|r|main|30")
KEEP+=("niko/r/reports/c1/test-c|niko|r|main|30")
KEEP+=("niko/r/reports/c2/test-a|niko|r|main|10")
KEEP+=("niko/r/reports/c2/test-b|niko|r|main|10")
KEEP+=("niko/r/reports/c2/test-c|niko|r|main|10")
TO_DELETE=()
apply_retention "$CONFIG"
[ "${#TO_DELETE[@]}" -eq 0 ]
}
@test "keepMin: 6 commits × 2 types, keepMin=3 → keeps 3 newest, deletes 3 oldest" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":3}}}
EOF
KEEP=()
local -a commits=(c1 c2 c3 c4 c5 c6)
local -a ages=(60 50 40 30 20 10)
local -a types=(jest pytest)
for i in "${!commits[@]}"; do
for t in "${types[@]}"; do
KEEP+=("niko/r/reports/${commits[$i]}/$t|niko|r|feature/x|${ages[$i]}")
done
done
TO_DELETE=()
apply_retention "$CONFIG"
# Sort by days ascending: c6(10d), c5(20d), c4(30d), c3(40d), c2(50d), c1(60d)
# keepMin=3: c6,c5,c4 kept; c3,c2,c1 deleted
[ "${#TO_DELETE[@]}" -eq 3 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/c3" ]]
[[ "${TO_DELETE[1]}" == "niko/r/reports/c2" ]]
[[ "${TO_DELETE[2]}" == "niko/r/reports/c1" ]]
}
# ---------------------------------------------------------------------------
# apply_retention — maxAge
# ---------------------------------------------------------------------------
@test "maxAge: report exceeding maxAge is deleted" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5}}}
EOF
KEEP=(
"niko/r/reports/c1/test|niko|r|main|100"
"niko/r/reports/c2/test|niko|r|main|50"
)
TO_DELETE=()
apply_retention "$CONFIG"
# c1 (100d) > 90, deleted; c2 (50d) < 90, kept
[ "${#TO_DELETE[@]}" -eq 1 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/c1/test" ]]
}
@test "maxAge deletes report-level dir, not commit-level" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":30,"keepMin":5}}}
EOF
KEEP=(
"niko/r/reports/c1/test-a|niko|r|main|100"
"niko/r/reports/c1/test-b|niko|r|main|20"
"niko/r/reports/c2/test-a|niko|r|main|10"
)
TO_DELETE=()
apply_retention "$CONFIG"
# Only test-a for c1 is old; test-b for c1 is young, c2 is young
[ "${#TO_DELETE[@]}" -eq 1 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/c1/test-a" ]]
}
# ---------------------------------------------------------------------------
# apply_retention — maxAge + keepMin interaction
# ---------------------------------------------------------------------------
@test "maxAge takes precedence over keepMin — aged report deleted, not counted in keepMin" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":30,"keepMin":2}}}
EOF
# 3 commits, 1 type each. c1 is old (100d), c2 and c3 are young.
# With keepMin=2: c1 should be deleted by maxAge, c2 and c3 kept.
# Without the continue after maxAge check, c1 would consume a keepMin slot.
KEEP=(
"niko/r/reports/c1/test|niko|r|main|100"
"niko/r/reports/c2/test|niko|r|main|10"
"niko/r/reports/c3/test|niko|r|main|5"
)
TO_DELETE=()
apply_retention "$CONFIG"
# c1 deleted by maxAge, c2 and c3 within keepMin=2
[ "${#TO_DELETE[@]}" -eq 1 ]
}
# ---------------------------------------------------------------------------
# apply_retention — sorting (newest first)
# ---------------------------------------------------------------------------
@test "sort order: newest commits processed first within same branch" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":2}}}
EOF
KEEP=(
"niko/r/reports/c1/test|niko|r|main|100"
"niko/r/reports/c2/test|niko|r|main|50"
"niko/r/reports/c3/test|niko|r|main|10"
)
TO_DELETE=()
apply_retention "$CONFIG"
# Sort by days ascending: c3(10d) 1st, c2(50d) 2nd, c1(100d) 3rd
# keepMin=2: c3 and c2 kept, c1 deleted
[ "${#TO_DELETE[@]}" -eq 1 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/c1" ]]
}
@test "sort order: branches sorted alphabetically" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":1}}}
EOF
KEEP=(
"niko/r/reports/c1/test|niko|r|z-branch|50"
"niko/r/reports/c2/test|niko|r|a-branch|60"
"niko/r/reports/c3/test|niko|r|m-branch|10"
)
TO_DELETE=()
apply_retention "$CONFIG"
# Alphabetical: a-branch, m-branch, z-branch
# Each has 1 commit, keepMin=1 → nothing deleted
[ "${#TO_DELETE[@]}" -eq 0 ]
}
@test "multi-branch: each branch has own keepMin counter" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":2}}}
EOF
KEEP=(
"niko/r/reports/c1/test|niko|r|branch-a|30"
"niko/r/reports/c2/test|niko|r|branch-a|20"
"niko/r/reports/c3/test|niko|r|branch-a|10"
"niko/r/reports/c4/test|niko|r|branch-b|60"
"niko/r/reports/c5/test|niko|r|branch-b|50"
"niko/r/reports/c6/test|niko|r|branch-b|40"
"niko/r/reports/c7/test|niko|r|branch-b|30"
)
TO_DELETE=()
apply_retention "$CONFIG"
# branch-a: 3 reports → keep 2 newest (c2,c3), delete 1 oldest (c1)
# branch-b: 4 reports → keep 2 newest (c6,c7), delete 2 oldest (c4,c5)
# Actually: Sort is by branch, then by days ascending
# branch-a processed first: c3(10d) 1st, c2(20d) 2nd (keep), c1(30d) 3rd (delete)
# branch-b processed next: c7(30d) 1st, c6(40d) 2nd (keep), c5(50d) 3rd (delete), c4(60d) 4th (delete)
[ "${#TO_DELETE[@]}" -eq 3 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/c1" ]]
[[ "${TO_DELETE[1]}" == "niko/r/reports/c5" ]]
[[ "${TO_DELETE[2]}" == "niko/r/reports/c4" ]]
}
# ---------------------------------------------------------------------------
# apply_retention — empty / edge cases
# ---------------------------------------------------------------------------
@test "empty KEEP array → nothing deleted" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":90,"keepMin":5}}}
EOF
KEEP=()
TO_DELETE=()
apply_retention "$CONFIG"
[ "${#TO_DELETE[@]}" -eq 0 ]
}
@test "TO_DELETE preserves Phase 2 entries after apply_retention (no new deletions)" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":10}}}
EOF
KEEP=(
"niko/r/reports/c1/test|niko|r|main|10"
"niko/r/reports/c2/test|niko|r|main|5"
)
TO_DELETE=(
"niko/r/reports/abc/branch-gone"
"niko/r/reports/def/repo-gone"
)
apply_retention "$CONFIG"
[ "${#TO_DELETE[@]}" -eq 2 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/abc/branch-gone" ]]
[[ "${TO_DELETE[1]}" == "niko/r/reports/def/repo-gone" ]]
}
@test "TO_DELETE preserves Phase 2 entries AND adds retention deletions" {
write_config <<'EOF'
{"branches":{"default":{"maxAgeDays":365,"keepMin":3}}}
EOF
KEEP=(
"niko/r/reports/c1/test|niko|r|main|40"
"niko/r/reports/c2/test|niko|r|main|30"
"niko/r/reports/c3/test|niko|r|main|20"
"niko/r/reports/c4/test|niko|r|main|10"
)
TO_DELETE=(
"niko/r/reports/abc/branch-gone"
)
apply_retention "$CONFIG"
# 1 pre-existing + 1 commit deleted (c1, oldest of 4, keepMin=3)
[ "${#TO_DELETE[@]}" -eq 2 ]
[[ "${TO_DELETE[0]}" == "niko/r/reports/abc/branch-gone" ]]
}
# ---------------------------------------------------------------------------
# branch_exists — mocking REPO_STATUS / REPO_BRANCHES_CACHE
# ---------------------------------------------------------------------------
@test "branch_exists: branch in list → return 0" {
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test-token"
REPO_BRANCHES_CACHE["owner/repo"]=$'main\nfeature/x'
REPO_STATUS["owner/repo"]="ok"
run branch_exists "owner" "repo" "main"
[ "$status" -eq 0 ]
}
@test "branch_exists: branch not in list → return 1" {
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test-token"
REPO_BRANCHES_CACHE["owner/repo"]=$'main\nfeature/x'
REPO_STATUS["owner/repo"]="ok"
run branch_exists "owner" "repo" "nonexistent"
[ "$status" -eq 1 ]
}
@test "branch_exists: cert error → exit 1 with [FATAL]" {
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test"
REPO_STATUS["owner/repo"]="cert_error"
run branch_exists "owner" "repo" "any-branch"
[ "$status" -eq 1 ]
[[ "$output" == *"[FATAL]"* ]]
}
@test "branch_exists: repo deleted → return 1" {
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test-token"
REPO_BRANCHES_CACHE["owner/repo"]="__REPO_DELETED__"
REPO_STATUS["owner/repo"]="deleted"
run branch_exists "owner" "repo" "any-branch"
[ "$status" -eq 1 ]
}
@test "branch_exists: network error → return 0 (fail-safe keep)" {
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test-token"
REPO_BRANCHES_CACHE["owner/repo"]="__REPO_ERROR__"
REPO_STATUS["owner/repo"]="error"
run branch_exists "owner" "repo" "any-branch"
[ "$status" -eq 0 ]
}
@test "branch_exists: empty GITEA_API_URL → return 0 (skip)" {
GITEA_API_URL=""
GITEA_TOKEN="test-token"
run branch_exists "owner" "repo" "any-branch"
[ "$status" -eq 0 ]
}
@test "branch_exists: empty GITEA_TOKEN → return 0 (skip)" {
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN=""
run branch_exists "owner" "repo" "any-branch"
[ "$status" -eq 0 ]
}
# ---------------------------------------------------------------------------
# repo_branches — git ls-remote error detection patterns
# ---------------------------------------------------------------------------
@test "error detection: 'command not found' does NOT trigger repo deleted" {
# This must NOT match — "bash: git: command not found" is NOT a repo deletion
local msg="bash: git: command not found"
run grep -qiE "fatal:.*(not found|repository.*not|could not read)" <<< "$msg"
[ "$status" -eq 1 ]
}
@test "error detection: 'fatal: repo not found' triggers repo deleted" {
# This MUST match — genuine git error for deleted/missing repo
local msg="fatal: repository 'https://gitea.app/owner/repo.git' not found"
run grep -qiE "fatal:.*(not found|repository.*not|could not read)" <<< "$msg"
[ "$status" -eq 0 ]
}
@test "error detection: 'could not read from remote' triggers repo deleted" {
local msg="fatal: could not read from remote repository"
run grep -qiE "fatal:.*(not found|repository.*not|could not read)" <<< "$msg"
[ "$status" -eq 0 ]
}
# ---------------------------------------------------------------------------
# git ls-remote integration (real git, temp repo)
# ---------------------------------------------------------------------------
@test "git ls-remote parsing: lists branches correctly" {
local tmpdir=$(mktemp -d)
git -C "$tmpdir" init -b main source >/dev/null 2>&1
git -C "$tmpdir/source" config user.email "test@test"
git -C "$tmpdir/source" config user.name "test"
git -C "$tmpdir/source" commit --allow-empty -m "init" >/dev/null 2>&1
git -C "$tmpdir/source" branch feature/x >/dev/null 2>&1
git clone --bare "$tmpdir/source" "$tmpdir/repo.git" >/dev/null 2>&1
local url="file://$tmpdir/repo.git"
local output
output=$(git ls-remote --heads "$url" 2>&1)
local branches
branches=$(echo "$output" | sed -n 's|.*refs/heads/||p')
echo "$branches" | grep -qxF "main"
[ "$?" -eq 0 ]
echo "$branches" | grep -qxF "feature/x"
[ "$?" -eq 0 ]
! echo "$branches" | grep -qxF "nonexistent"
rm -rf "$tmpdir"
}
# ---------------------------------------------------------------------------
# repo_branches — retry + error output (using git mock)
# ---------------------------------------------------------------------------
@test "repo_branches: success returns branches immediately" {
local mockdir=$(mktemp -d)
cat > "$mockdir/git" << 'SCRIPT'
#!/usr/bin/env bash
echo "abc123 refs/heads/main"
echo "def456 refs/heads/feature/x"
SCRIPT
chmod +x "$mockdir/git"
local save_PATH="$PATH"
export PATH="$mockdir:$PATH"
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test"
REPO_BRANCHES_CACHE=()
REPO_STATUS=()
run repo_branches "owner" "repo"
[ "$status" -eq 0 ]
[[ "$output" == *"main"* ]]
[[ "$output" == *"feature/x"* ]]
export PATH="$save_PATH"
rm -rf "$mockdir"
}
@test "repo_branches: retries 3 times on transient error" {
local mockdir=$(mktemp -d)
cat > "$mockdir/git" << 'SCRIPT'
#!/usr/bin/env bash
echo "call" >> "$MOCKDIR/count"
echo "fatal: unable to access 'https://...'" >&2
exit 1
SCRIPT
chmod +x "$mockdir/git"
# Inject mockdir path into mock script via env var
sed -i '' "s|\$MOCKDIR|$mockdir|g" "$mockdir/git"
local save_PATH="$PATH"
export PATH="$mockdir:$PATH"
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test"
REPO_BRANCHES_CACHE=()
REPO_STATUS=()
local start=$SECONDS
run repo_branches "owner" "repo"
[ "$status" -eq 3 ]
[[ "$output" == *"[WARN] git-pages.retention"* ]]
[[ "$output" == *"keeping all reports"* ]]
[[ "$output" == *"git output:"* ]]
[[ "$output" == *"unable to access"* ]]
[ $(cat "$mockdir/count" | wc -l) -eq 3 ]
[ $(( SECONDS - start )) -ge 18 ]
export PATH="$save_PATH"
rm -rf "$mockdir"
}
@test "repo_branches: certificate error → [ERROR] + return 1" {
local mockdir=$(mktemp -d)
cat > "$mockdir/git" << 'SCRIPT'
#!/usr/bin/env bash
echo "call" >> "$MOCKDIR/count"
echo "fatal: unable to access 'https://gitea.app/owner/repo.git/': server certificate verification failed. CAfile: none CRLfile: none" >&2
exit 1
SCRIPT
chmod +x "$mockdir/git"
sed -i '' "s|\$MOCKDIR|$mockdir|g" "$mockdir/git"
local save_PATH="$PATH"
export PATH="$mockdir:$PATH"
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test"
REPO_BRANCHES_CACHE=()
REPO_STATUS=()
run repo_branches "owner" "repo"
[ "$status" -eq 2 ]
[[ "$output" == *"[ERROR]"* ]]
[[ "$output" == *"certificate verification"* ]]
[[ "$output" == *"git output:"* ]]
[[ "$output" == *"unable to access"* ]]
export PATH="$save_PATH"
rm -rf "$mockdir"
}
@test "repo_branches: repo not found returns immediately (no retry)" {
local mockdir=$(mktemp -d)
cat > "$mockdir/git" << 'SCRIPT'
#!/usr/bin/env bash
echo "call" >> "$MOCKDIR/count"
echo "fatal: repository 'https://gitea.app/owner/repo.git' not found" >&2
exit 1
SCRIPT
chmod +x "$mockdir/git"
sed -i '' "s|\$MOCKDIR|$mockdir|g" "$mockdir/git"
local save_PATH="$PATH"
export PATH="$mockdir:$PATH"
GITEA_API_URL="https://gitea.example.com"
GITEA_TOKEN="test"
REPO_BRANCHES_CACHE=()
REPO_STATUS=()
run repo_branches "owner" "repo"
[ "$status" -eq 1 ]
[[ "$output" == *"REPO DELETED"* ]]
[[ "$output" != *"[WARN]"* ]]
[ $(cat "$mockdir/count" | wc -l) -eq 1 ]
export PATH="$save_PATH"
rm -rf "$mockdir"
}
+2
View File
@@ -12,6 +12,8 @@ echo "gitops-dispatch: validating env vars..."
: "${GITEA_API_URL:?}" : "${GITEA_API_URL:?}"
: "${GITEA_TOKEN:?}" : "${GITEA_TOKEN:?}"
TIMEOUT="${GITOPS_DISPATCH_TIMEOUT:-30}"
echo "gitops-dispatch: constructing inputs..." echo "gitops-dispatch: constructing inputs..."
INPUTS=$(jq -nc \ INPUTS=$(jq -nc \
--arg file "$GITOPS_FILE" \ --arg file "$GITOPS_FILE" \
+21 -4
View File
@@ -368,9 +368,18 @@ Pakkaa ja pushee Helm-chartin OCI-registryyn. Käyttää `alpine/helm`-konttia.
```yaml ```yaml
HELM_REGISTRY: gitea.app.keskikuja.site/niko HELM_REGISTRY: gitea.app.keskikuja.site/niko
VERSION_FILE: platform-helm/Chart.yaml # chart-hakemisto + versionlähde VERSION_FILE: platform-helm/Chart.yaml # versionlähde, chart_path määrää chart-hakemiston
``` ```
**Inputit:**
| Parametri | Pakollinen | Kuvaus |
|-----------|------------|--------|
| `env_json` | Kyllä | Konffi `gitea-env.conf`:stä |
| `version` | Kyllä | Version string (check-version output) |
| `chart_path` | Kyllä | Polku Chart.yaml-hakemistoon (esim. `platform-helm`) |
| `extra_dependency_paths` | Ei | Pilkulla erotellut polut subcharttien dependeinceille |
**Käyttö reitittimessä:** **Käyttö reitittimessä:**
```yaml ```yaml
@@ -382,11 +391,19 @@ helm-build-push:
with: with:
env_json: ${{ needs.load-config.outputs.env_json }} env_json: ${{ needs.load-config.outputs.env_json }}
version: ${{ needs.check-version.outputs.version }} version: ${{ needs.check-version.outputs.version }}
chart_path: platform-helm
# extra_dependency_paths: subchart-a,subchart-b # tarvittaessa
``` ```
Chart-hakemisto johdetaan `VERSION_FILE`-polusta: `dirname "${VERSION_FILE}"`. `chart_path` on eksplisiittinen polku chart-hakemistoon (esim. `platform-helm`).
Jos `VERSION_FILE` on `Chart.yaml`, konteksti on juuri. Jos `platform-helm/Chart.yaml`, `VERSION_FILE` määrää version lähteen (`Chart.yaml:n` `version`-kenttä) —
konteksti on `platform-helm/`. nämä voivat olla eri polkuja, mutta tyypillisesti molemmat osoittavat samaan
chart-hakemistoon.
**`extra_dependency_paths`:** Jos chartilla on alikarttoja (subchartteja) jotka
vaativat `helm dependency update` -ajon ennen päächartin buildia, anna niiden
polut pilkulla eroteltuna. Provider ajaa `helm dependency update` jokaiselle
polulle ennen päächartin buildia.
**Yksittäisten Helm-UI-linkkien raportointi:** `HELM_UI_URL` on **Yksittäisten Helm-UI-linkkien raportointi:** `HELM_UI_URL` on
tarkoitettu yleiselle registry UI:lle — provider muodostaa linkin tarkoitettu yleiselle registry UI:lle — provider muodostaa linkin
+112 -305
View File
@@ -1,10 +1,9 @@
--- ---
name: gitops-update name: gitops-update
description: | description: |
Setting up GitOps version updates: GitOps-repo workflow template, code Getting GitOps configuration updates working for a consumer project —
repo dispatch, secret requirements, and two-repo commit-status pattern. GitOps repo setup, consumer pipeline wiring, secrets, and commit-status
Activates when the user needs to wire up artifact builds to GitOps output.
configuration updates.
activation-gate: | activation-gate: |
User mentions GitOps update, gitops-update, dispatch to another repo, User mentions GitOps update, gitops-update, dispatch to another repo,
two-repo version bump, cross-repo deployment, or wiring build output to two-repo version bump, cross-repo deployment, or wiring build output to
@@ -13,47 +12,26 @@ category: ci
impact: high impact: high
--- ---
# GitOps Update — Provider-palvelu # GitOps Update — consumer setup
`scripts/gitops-update.sh` ja `scripts/dispatch-workflow.sh` muodostavat ## What you need
GitOps-päivityspalvelun. Artifact buildataan code repossa, minkä jälkeen
code repo dispatchaa GitOps-repoon, joka päivittää konfiguraatiotiedoston
ja pushaa muutoksen.
## Arkkitehtuuri - **GitOps repo** — holds the configuration files (e.g. `Chart.yaml`, `values.yaml`)
- **Consumer repo** — builds artifacts and triggers the update
- **Bottitoken** — Gitea token with write access to the GitOps repo only
Kaksi erillistä repoa, eristetyt oikeudet: Two repos, isolated access. The consumer never writes to GitOps directly;
it dispatches a workflow that clones, updates, commits, and pushes.
``` ---
Code repo GitOps repo
(build & push artifact) (konfiguraatiot)
build & push onnistuu (v0.2.3) ## 1. GitOps-repo setup
│ dispatch ci-main.yml
│ {file, yq_tpl, version, source_repo, source_commit}
└────────────────────────────────────→┐
dispatch-workflow.sh pollaa ←─────────┘
code repo asettaa │ git clone, yq update,
oman commit-statusnsa │ git commit + push
dispatchin exit-koodilla │ status GitOps-repoon
```
**Token-periaate:** Vain GitOps-repoon kirjoitetaan. Code repo asettaa Create `.gitea/workflows/gitops-service.yaml`:
oman commit-statusnsa dispatch-kutsun exit-koodin perusteella omalla
auto-tokenillaan. GitOps-repon auto-token ei tarvitse oikeuksia code
repoon.
## GitOps-repon workflow (ci-main.yml)
GitOps-repoon luodaan `.gitea/workflows/ci-main.yml`:
```yaml ```yaml
name: GitOps Update name: GitOps Update
run-name: "GitOps Service (${{ inputs.dispatch_id || 'manual' }})" run-name: "GitOps (${{ inputs.dispatch_id || 'manual' }})"
on: on:
workflow_dispatch: workflow_dispatch:
inputs: inputs:
@@ -86,7 +64,6 @@ env:
SOURCE_REPO: ${{ inputs.source_repo }} SOURCE_REPO: ${{ inputs.source_repo }}
SOURCE_COMMIT: ${{ inputs.source_commit }} SOURCE_COMMIT: ${{ inputs.source_commit }}
GITOPS_REPO: ${{ github.repository }} GITOPS_REPO: ${{ github.repository }}
GITOPS_BRANCH: ${{ github.ref_name }}
GITEA_API_URL: ${{ gitea.server_url }} GITEA_API_URL: ${{ gitea.server_url }}
GIT_TAG_PREFIX: ${{ inputs.git_tag_prefix || '' }} GIT_TAG_PREFIX: ${{ inputs.git_tag_prefix || '' }}
@@ -95,18 +72,15 @@ jobs:
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- uses: actions/checkout@v4 - uses: actions/checkout@v4
with: with:
repository: niko/gitea-ci-library repository: niko/gitea-ci-library
path: .ci path: .ci
- name: Install yq - name: Install yq
run: | run: |
wget -qO /usr/local/bin/yq \ wget -qO /usr/local/bin/yq \
https://github.com/mikefarah/yq/releases/latest/download/yq_linux_amd64 https://github.com/mikefarah/yq/releases/latest/download/yq_linux_amd64
chmod +x /usr/local/bin/yq chmod +x /usr/local/bin/yq
- name: Run GitOps update - name: Run GitOps update
env: env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
@@ -114,297 +88,130 @@ jobs:
bash .ci/scripts/gitops-update.sh bash .ci/scripts/gitops-update.sh
``` ```
**Huomiot:** > **⚠️ yq ladataan lennossa.** Tämä on väliaikainen kompromissi. Myöhemmin
- `GITEA_TOKEN` on Gitean auto-token — scopeutuu GitOps-repoon, riittää > julkaistaan Docker Hubiin custom CI-kontti, jossa nodejs + git + yq
cloneen, committiin, pushiin ja commit-statusiin GitOps-repossa > valmiina. Sama patterni kuin `ci-bats` ja `ci-cucumber`.
- `run-name` ja `dispatch_id` mahdollistavat dispatchaavan skriptin tunnistaa > Ks. `skills/ci-container-build/SKILL.md`.
tämän workflow-runin yksiselitteisesti `display_title`-kentästä, vaikka
samassa repossa olisi samanaikaisia ajoja
- yq ladataan lennossa (kompromissi, ks. "Tuleva CI-kontti")
### Tulossa: custom CI-kontti Key points:
- `run-name` must include `dispatch_id` — the consumer's poll step uses it to find the run
- `secrets.GITEA_TOKEN` is the **auto-token** — write access to the GitOps repo only, no consumer access needed
- Commit message becomes `"[skip ci] gitops: update version to X.Y.Z"` — used by consumer to find the commit SHA
Nykyinen job lataa yq:n lennossa. Myöhemmin rakennetaan oma kontti ---
(`ci-gitops`), jossa on nodejs + git + yq valmiina. Sama patterni kuin
`ci-bats` ja `ci-cucumber`. Ks. `skills/ci-container-build/SKILL.md`.
## Code-repon dispatch-step ## 2. Consumer-repo setup
Code repo dispatchaa GitOps-repon workflown artifact buildin onnistuttua: ### 2.1 Token
Create a Gitea token with write access to the GitOps repo:
1. Gitea → `Settings``Applications``Generate Token`
2. Select the GitOps repo, grant write access
3. Save as an Actions secret in the consumer repo: **`GITOPS_DISPATCH_TOKEN`**
### 2.2 Pipeline call
Add a job after your build step that calls the dispatch workflow:
```yaml ```yaml
gitops-update: gitops-update:
needs: [helm-build-push] needs: [build-push]
if: success() if: success()
runs-on: ubuntu-latest uses: niko/gitea-ci-library/.gitea/workflows/gitops-dispatch.yml@v1
steps: secrets: inherit
- uses: actions/checkout@v4 with:
env_json: ${{ needs.load-config.outputs.env_json }}
- uses: actions/checkout@v4 version: ${{ needs.version.outputs.version }}
with: GITOPS_FILE: dev/Chart.yaml
repository: niko/gitea-ci-library GITOPS_YQ_TPL: '.version = "{{VERSION}}"'
path: .ci GITOPS_REPO: niko/your-gitops-repo
- name: Dispatch GitOps update
id: dispatch
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
run: |
INPUTS=$(jq -nc \
--arg file "dev/Chart.yaml" \
--arg yq_tpl '(.dependencies[] | select(.name == "agent-platform-helm") | .version) = "{{VERSION}}"' \
--arg version "${{ needs.check-version.outputs.version }}" \
--arg source_repo "${{ github.repository }}" \
--arg source_commit "${{ github.sha }}" \
'{file: $file, yq_tpl: $yq_tpl, version: $version, source_repo: $source_repo, source_commit: $source_commit}')
OUTPUT=$(bash .ci/scripts/dispatch-workflow.sh \
"niko/agent-platform-gitops" \
"ci-main.yml" \
"main" \
"$INPUTS" \
"${{ fromJson(needs.load-config.outputs.env_json).GITEA_API_URL }}" \
"${{ secrets.GITEA_TOKEN }}" \
"30")
echo "$OUTPUT"
GITOPS_COMMIT=$(echo "$OUTPUT" | grep '^GITOPS_COMMIT=' | cut -d= -f2)
echo "gitops_commit=$GITOPS_COMMIT" >> "$GITHUB_OUTPUT"
``` ```
### Multi-artifact pipeline (kontti + helm) This single job handles: dispatch → poll → find commit SHA → set commit-status on your commit → produce `GITOPS_SUMMARY` output.
Yksi main-haaran build tuottaa usein sekä Docker-imagen että Helm-chartin. ### 2.3 Parameters
Kumpikin artefakti dispatchaa oman GitOps-päivityksensä rinnakkain:
```yaml | Input | Required | Description |
gitops-helm:
needs: [helm-build-push]
if: success()
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v4
with:
repository: niko/gitea-ci-library
path: .ci
- name: Update helm version
id: helm
run: |
INPUTS=$(jq -nc \
--arg file "dev/Chart.yaml" \
--arg yq_tpl '(.dependencies[] | select(.name == "git-pages") | .version) = "{{VERSION}}"' \
--arg version "${{ needs.check-version.outputs.version }}" \
--arg source_repo "${{ github.repository }}" \
--arg source_commit "${{ github.sha }}" \
--arg git_tag_prefix "helm" \
'{dispatch_id: "", file: $file, yq_tpl: $yq_tpl, version: $version, source_repo: $source_repo, source_commit: $source_commit, git_tag_prefix: $git_tag_prefix}')
OUTPUT=$(bash .ci/scripts/dispatch-workflow.sh \
"niko/gitea-ci-gitops-tests" "gitops-service.yaml" "main" \
"$INPUTS" "${{ fromJson(needs.load-config.outputs.env_json).GITEA_API_URL }}" \
"${{ secrets.GITOPS_DISPATCH_TOKEN }}" "30")
echo "$OUTPUT"
echo "helm_commit=$(echo "$OUTPUT" | grep '^GITOPS_COMMIT=' | cut -d= -f2)" >> "$GITHUB_OUTPUT"
gitops-docker:
needs: [docker-build-push]
if: success()
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v4
with:
repository: niko/gitea-ci-library
path: .ci
- name: Update docker tag
id: docker
run: |
INPUTS=$(jq -nc \
--arg file "dev/values.yaml" \
--arg yq_tpl '.service.tag = "{{VERSION}}"' \
--arg version "${{ needs.check-version.outputs.version }}" \
--arg source_repo "${{ github.repository }}" \
--arg source_commit "${{ github.sha }}" \
--arg git_tag_prefix "docker" \
'{dispatch_id: "", file: $file, yq_tpl: $yq_tpl, version: $version, source_repo: $source_repo, source_commit: $source_commit, git_tag_prefix: $git_tag_prefix}')
OUTPUT=$(bash .ci/scripts/dispatch-workflow.sh \
"niko/gitea-ci-gitops-tests" "gitops-service.yaml" "main" \
"$INPUTS" "${{ fromJson(needs.load-config.outputs.env_json).GITEA_API_URL }}" \
"${{ secrets.GITOPS_DISPATCH_TOKEN }}" "30")
echo "$OUTPUT"
echo "docker_commit=$(echo "$OUTPUT" | grep '^GITOPS_COMMIT=' | cut -d= -f2)" >> "$GITHUB_OUTPUT"
```
Kaksi dispatchia, kaksi eri tiedostoa, kaksi eri `GIT_TAG_PREFIX`-arvoa.
Kummallakin on oma commit-status-linja ja oma summary-rivi.
`dispatch-workflow.sh` hoitaa rinnakkaisuuden `display_title`-matchauksella.
**GITEA_TOKEN dispatch-vaiheessa:** Tarvitaan manuaalinen token,
jolla on **write-oikeus GitOps-repoon** (esim. org-tason token).
Code-repon auto-token ei oikeuta dispatchaamaan toiseen repoon.
Token luodaan Giteassa: `Settings → Applications → Generate Token`
ja asetetaan code-repoon Actions Secretiksi.
### Commit-status dispatchin perusteella
`dispatch-workflow.sh` tulostaa `GITOPS_COMMIT=<sha>` stdoutiin onnistuneen
GitOps-päivityksen jälkeen. Code repo parsii sen ja asettaa commit-statusin
linkillä GitOps-committiin:
```yaml
- name: Set commit-status with GitOps link
if: always()
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
GITEA_API_URL: ${{ fromJson(needs.load-config.outputs.env_json).GITEA_API_URL }}
GITOPS_COMMIT: ${{ steps.dispatch.outputs.gitops_commit }}
VERSION: ${{ needs.check-version.outputs.version }}
run: |
GITOPS_URL="${GITEA_API_URL}/niko/agent-platform-gitops/commit/${GITOPS_COMMIT}"
CTX="gitops/$(basename ${{ github.repository }})"
DESC="Deploy to dev ${VERSION}"
if [ -n "$GITOPS_COMMIT" ]; then
bash .ci/scripts/report-status.sh success "$DESC" "$CTX" "" "$GITOPS_URL"
else
bash .ci/scripts/report-status.sh success "$DESC" "$CTX"
fi
```
`dispatch-workflow.sh` palauttaa:
- exit 0 = GitOps-päivitys onnistui (+ `GITOPS_COMMIT=<sha>`)
- exit 1 = GitOps-päivitys failasi
- exit 124 = aikakatkaisu (360 min oletus)
### Loppuraportti (report-summary)
Code-repon viimeinen job (`report-summary`) lisää GitOps-päivityksestä
rivin GITHUB_STEP_SUMMARYyn:
```yaml
- name: GitOps summary
if: always()
env:
GITEA_API_URL: ${{ fromJson(needs.load-config.outputs.env_json).GITEA_API_URL }}
GITOPS_COMMIT: ${{ steps.dispatch.outputs.gitops_commit }}
VERSION: ${{ needs.check-version.outputs.version }}
run: |
if [ -n "$GITOPS_COMMIT" ]; then
LINK="${GITEA_API_URL}/niko/agent-platform-gitops/commit/${GITOPS_COMMIT}"
else
LINK="#"
fi
cat >> "$GITHUB_STEP_SUMMARY" << 'GITOPS'
## GitOps updates
| Component | Version | Status | Commit |
|-----------|---------|--------|--------|
| agent-platform-helm | __VERSION__ | __STATUS__ | [link](__LINK__) |
GITOPS
sed -i "s|__VERSION__|${VERSION}|; s|__STATUS__|${{ job.status }}|; s|__LINK__|${LINK}|" \
"$GITHUB_STEP_SUMMARY"
```
## Secretit ja tokenit
| Secret | Missä | Scope | Kuvaus |
|--------|-------|-------|--------|
| `GITEA_TOKEN` (auto) | Code repo | Vain code repo | Asettaa commit-statusin dispatchin jälkeen |
| `GITEA_TOKEN` (auto) | GitOps repo | Vain GitOps repo | Klooni, push, commit-status GitOps-repossa |
| `GITOPS_DISPATCH_TOKEN` (manuaalinen) | Code repo | Write GitOps-repoon | Dispatchaa GitOps-repon workflow |
**Tokenin luonti:**
1. Gitea → `Settings``Applications``Generate Token`
2. Valitse repo-oikeudet: valitse GitOps-repo, anna write-oikeudet
3. Token asetetaan code-repoon: `{repo} → Settings → Actions Secrets`
4. Salaisuuden nimi: esim. `GITOPS_DISPATCH_TOKEN`
## Provider-skriptit
### `scripts/gitops-update.sh`
Ajaan GitOps-repon workflow'ssa. Päivittää konfiguraatiotiedoston yq:llä,
committaa ja pushaa. Asettaa commit-statuksen vain GitOps-repoon.
**Input-ympäristömuuttujat:**
| Muuttuja | Pakollinen | Kuvaus |
|---|---|---| |---|---|---|
| `INPUT_FILE` | Kyllä | Tiedosto GitOps-repossa (esim. `dev/Chart.yaml`) | | `env_json` | Yes | Config JSON with `GITEA_API_URL`, optional `GIT_TAG_PREFIX` (for multi-component repos) |
| `YQ_TPL` | Kyllä | yq-lauseke `{{VERSION}}`-placeholderilla | | `version` | Yes | Version to write (e.g. `0.2.3`) |
| `VERSION` | Kyllä | Uusi versio (esim. `0.2.3`) | | `GITOPS_FILE` | Yes | Path in GitOps repo (e.g. `dev/Chart.yaml`) |
| `SOURCE_REPO` | Kyllä | Code-repo slug (esim. `org/app`) | | `GITOPS_YQ_TPL` | Yes | yq expression, `{{VERSION}}` is replaced at runtime |
| `SOURCE_COMMIT` | Kyllä | Code-repon commit SHA | | `GITOPS_REPO` | Yes | GitOps repo slug (e.g. `niko/agent-platform-gitops`) |
| `GITOPS_REPO` | Kyllä | GitOps-repo slug |
| `GITEA_API_URL` | Kyllä | Gitean API-URL |
| `GITEA_TOKEN` | Kyllä | Gitea API-token (write GitOps-repoon) |
| `GITOPS_BRANCH` | Ei | Branch (oletus `main`) |
| `GIT_TAG_PREFIX` | Ei | Komponentin tag-prefix status-nimeämiseen (esim. `agent-platform-helm`) |
| `GITOPS_CLONE_URL` | Ei | Yliajaa clone-URL (esim. eri protokolla) |
| `GITOPS_TARGET_DIR` | Ei | Yliajaa clone-kohdehakemisto |
**Commit-status muoto:** ### 2.4 Output
GitOps-repoon asetetaan commit-status: The workflow produces a `summary` output in pipe format:
| Kenttä | Formaatti | Esimerkki | ```
|--------|-----------|-----------| component|version|status|commit_sha|repo
| Context | `{repo}/{GIT_TAG_PREFIX} {RUN_ID}` tai `{repo} {RUN_ID}` | `gitea-ci-library/agent-platform-helm 473` | agent-platform-helm|0.2.3|success|abc789def|niko/agent-platform-gitops
| Description | `Install to {env} {version}` | `Install to dev 0.2.0` | ```
| Target URL | Linkki code-repon committiin | `/niko/gitea-ci-library/commit/abc123` |
Jos tiedosto on jo halutussa versiossa (ei muutoksia), status saa descriptionin `Install to {env} {version} — no change`. Commit-pushia ei tehdä, GitOps-repo pysyy muuttumattomana. Pass it to `report-summary.yml` for the pipeline summary:
- `{env}` parsitaan `INPUT_FILE`:stä (`dev/Chart.yaml``dev`) ```yaml
- `{repo}` parsitaan `SOURCE_REPO`:sta (`niko/gitea-ci-library``gitea-ci-library`) report-summary:
- `{GIT_TAG_PREFIX}` tulee env-varista (sama kuin `gitea-env.conf`:ssa) needs: [load-config, gitops-update]
if: always()
uses: niko/gitea-ci-library/.gitea/workflows/report-summary.yml@main
with:
env_json: ${{ needs.load-config.outputs.env_json }}
suites: bats cucumber
gitops: ${{ needs.gitops-update.outputs.summary }}
```
### `scripts/dispatch-workflow.sh` ---
Dispatchaa workflow_dispatchin kohderepoon ja pollaa valmistumista. ## 3. Token summary
Generoi automaattisesti `dispatch_id`-tunnisteen, lisää sen dispatch-
inputteihin ja tunnistaa workflow-runin kohdereposta `display_title`-
kentän perusteella. Toimii luotettavasti vaikka samassa repossa olisi
useita samanaikaisia dispatch-attribuutioita.
**Argumentit:** | Token | Where | Scope | Purpose |
|---|---|---|---|
| `GITOPS_DISPATCH_TOKEN` (manual) | Consumer secrets | write GitOps repo | Dispatches the GitOps workflow |
| `GITHUB_TOKEN` (auto) | Consumer workflow | write consumer repo | Sets commit-status on consumer's commit |
| `GITEA_TOKEN` (auto) | GitOps workflow | write GitOps repo | Clone, push, commit-status in GitOps repo |
| # | Pakollinen | Kuvaus | ---
|---|------------|--------|
| 1 | Kyllä | Kohderepo (esim. `niko/agent-platform-gitops`) |
| 2 | Kyllä | Workflow-tiedosto (esim. `ci-main.yml`) |
| 3 | Kyllä | Branch/ref |
| 4 | Kyllä | Inputs JSON |
| 5 | Kyllä | Gitea API URL |
| 6 | Kyllä | Gitea token |
| 7 | Ei | Aikakatkaisu minuutteina (oletus 360) |
Kutsujan ei tarvitse välittää `dispatch_id`:tä — skripti generoi sen ## 4. What happens at runtime
itse ja lisää inputteihin ennen dispatchia.
## [skip ci] 1. Consumer's `gitops-dispatch.yml` generates a unique `dispatch_id` and POSTs it to the GitOps repo
2. GitOps workflow clones its own repo, applies `yq`, commits + pushes
3. Consumer polls the GitOps repo's runs until the workflow completes
4. Consumer lists recent commits and finds the matching one by commit message `"gitops: update version to X.Y.Z"`
5. Consumer sets commit-status `gitops/{repo}[/{prefix}]` on its own commit with a link to the exact GitOps commit
6. If no matching commit is found (no change or error), the job fails
7. On failure, `GITOPS_SUMMARY` still flows through `report-summary` with `status=failure`
Commit-viestissä on `[skip ci]`, joka estää GitActions-runneria ---
triggeröimästä uutta CI-ajoa GitOps-repoon pushista. Näin vältetään
ääretön trigger-loop.
## Race condition ## 5. GIT_TAG_PREFIX (optional)
`dispatch-workflow.sh` tunnistaa jokaisen dispatchatun runin uniikilla If the same consumer repo dispatches updates for multiple components (e.g. Docker image + Helm chart), set `GIT_TAG_PREFIX` in your `gitea-env.conf`:
`dispatch_id`-tunnisteella `display_title`-kentästä. Vaikka useampi
artifakti dispatchaisi samaan aikaan ja useita workflow-runeja olisi
käynnissä rinnakkain, jokainen skripti löytää oikean runinsa.
## Sääntöjä ```
GIT_TAG_PREFIX=docker/
```
1. **Token ei kirjoita code repoon.** GitOps-repon workflow ei tarvitse Each component gets its own commit-status context:
oikeuksia code repoon. Kaikki status-kutsut kohdistuvat vain
GitOps-repoon. Code repo asettaa oman statusnsa itse. | Prefix | Context |
2. **Ei provider-workflowta.** GitOps-päivitys ei ole reusable workflow. |---|---|
GitOps-repo ajaa `scripts/gitops-update.sh`:n suoraan. | (empty) | `gitops/agent-platform` |
3. **Vain `workflow_dispatch`.** GitOps-repon workflow:ta ei triggeröidä | `docker/` | `gitops/agent-platform/docker` |
pushista — se laukeaa vain dispatch-kutsusta. | `helm/` | `gitops/agent-platform/helm` |
4. **Dispatch ei palauta tarkkaa SHA:**ta. Code repo ei tiedä GitOps-
commitin SHA:ta ennen dispatch-valmistumista. Status asetetaan This prevents status overwrites between parallel dispatch jobs.
dispatchin exit-koodin perusteella, ei GitOps-commitin tiedoilla.
5. **`dispatch_id` on pakollinen kohde-workflow'ssa** — ilman sitä ---
`dispatch-workflow.sh` ei löydä oikeaa runia moniajo-tilanteessa.
6. **`[skip ci]` commit-viestissä.** Pakollinen trigger-loopin estoon. ## 6. What you do NOT need to know
- How `gitops-update.sh` works internally
- How the polling finds the run
- How the commit SHA is extracted
- Race condition handling
- CI container plans
All of that is handled by `gitops-dispatch.yml`. You just call it.