Skip to content

Commit 42fe7e7

Browse files
committed
PANDARIA: Merge tag 'v0.9.4' into release/v0.9-ent
2 parents 38cf318 + 5b69b4f commit 42fe7e7

18 files changed

Lines changed: 389 additions & 341 deletions

File tree

.github/renovate.json

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,6 @@
1313
],
1414
"prHourlyLimit": 2,
1515
"enabledManagers": [
16-
"droneci",
1716
"dockerfile",
1817
"github-actions",
1918
"helm-values",

.github/workflows/ci.yaml

Lines changed: 15 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -30,41 +30,32 @@ jobs:
3030
fail-fast: false
3131
matrix:
3232
os:
33-
- org-cnrancher-runner-dind-x64
34-
- org-cnrancher-runner-dind-arm64
33+
- ubuntu-latest
34+
- ubuntu-24.04-arm
3535
runs-on: ${{ matrix.os }}
3636
steps:
3737
- name : Checkout repository
3838
# https://github.com/actions/checkout/releases/tag/v4.1.1
39-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
40-
41-
- name: Setup Go
42-
# https://github.com/actions/setup-go/releases/tag/v5.0.0
43-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
44-
with:
45-
go-version-file: 'go.mod'
46-
- name: Install golangci-lint
47-
uses: golangci/golangci-lint-action@55c2c1448f86e01eaae002a5a3a9624417608d84 # v6.5.2
48-
with:
49-
version: v1.64.8
39+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
40+
5041

5142
- name: Set arch variable
5243
shell: bash
5344
run: |
5445
case "${{ runner.arch }}" in
5546
"X64" )
56-
echo "ARCH=amd64" >> $GITHUB_ENV
47+
echo "PLATFORM_ARCH=amd64" >> $GITHUB_ENV
5748
;;
5849
"ARM64" )
59-
echo "ARCH=arm64" >> $GITHUB_ENV
50+
echo "PLATFORM_ARCH=arm64" >> $GITHUB_ENV
6051
;;
6152
esac
6253
6354
- name: Install dependencies
6455
shell: bash
6556
run: |
66-
curl -sL https://get.helm.sh/helm-v3.13.3-linux-${ARCH}.tar.gz | sudo tar xvzf - -C /usr/local/bin --strip-components=1
67-
curl -sL https://dl.k8s.io/v1.28.11/kubernetes-client-linux-${ARCH}.tar.gz | sudo tar xvzf - -C /usr/local/bin --strip-components=3
57+
curl -sL https://get.helm.sh/helm-v3.13.3-linux-${PLATFORM_ARCH}.tar.gz | sudo tar xvzf - -C /usr/local/bin --strip-components=1
58+
curl -sL https://dl.k8s.io/v1.28.11/kubernetes-client-linux-${PLATFORM_ARCH}.tar.gz | sudo tar xvzf - -C /usr/local/bin --strip-components=3
6859
6960
# TODO: Pull this next one out once there's a helm-release for rancher 2.9
7061
- name: Checkout rancher/rancher and build the chart
@@ -77,25 +68,20 @@ jobs:
7768
tar cfz "${{ runner.temp }}/rancher.tgz" -C build/chart/rancher .
7869
popd
7970
71+
- name: Build, Test, and Package
72+
run: make ci
73+
8074
- name: install K3d
81-
run: ./.github/workflows/scripts/install-k3d.sh
82-
env:
83-
K3D_VERSION: latest
84-
85-
- name: "PANDARIA: install make"
8675
run: |
87-
sudo apt update
88-
sudo apt install -y build-essential
89-
90-
- name: ci
91-
run: make ci
76+
./.github/workflows/scripts/install-k3d.sh
77+
sudo mv ./bin/k3d /usr/local/bin/k3d
9278
9379
- name: setup cluster
9480
run: ./.github/workflows/scripts/setup-cluster.sh
9581
env:
9682
CLUSTER_NAME: webhook
9783
K3S_VERSION: v1.28.9-k3s1
98-
ARCH: "${{ matrix.archBox.arch }}"
84+
ARCH: "${PLATFORM_ARCH}"
9985

10086
- name: import image
10187
run: k3d image import dist/rancher-webhook-image.tar -c webhook
@@ -113,7 +99,7 @@ jobs:
11399
- name: Run integration tests
114100
run: ./.github/workflows/scripts/integration-test-ci
115101
env:
116-
ARCH: "${ARCH}"
102+
ARCH: "${PLATFORM_ARCH}"
117103
CLUSTER_NAME: webhook
118104
IMAGE_REPO: cnrancher/webhook
119105
IMAGE_TAG: "${{ env.IMAGE_TAG }}"

.github/workflows/publish-head.yaml

Lines changed: 28 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,9 @@ jobs:
2121
- arm64
2222
steps:
2323
- name : Checkout repository
24-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
24+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
2525
- name: Setup Go
26-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
26+
uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0
2727
with:
2828
go-version-file: 'go.mod'
2929
- name: Build and package
@@ -54,7 +54,7 @@ jobs:
5454
needs: build
5555
steps:
5656
- name : Checkout repository
57-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
57+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
5858
- name: Download the artifacts
5959
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
6060
with:
@@ -65,31 +65,46 @@ jobs:
6565
mkdir -p bin/
6666
cp -v dist/artifacts/webhook-linux-${{ matrix.arch }} bin/webhook
6767
chmod +x bin/webhook
68-
# PANDARIA
68+
6969
# - name: "Read vault secrets"
70-
# uses: rancher-eio/read-vault-secrets@main
70+
# uses: rancher-eio/read-vault-secrets@0da85151ad1f19ed7986c41587e45aac1ace74b6 # v3
7171
# with:
7272
# secrets: |
7373
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
7474
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
75+
7576
- name: Set up QEMU
76-
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
77+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
7778
- name: Set up Docker Buildx
78-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
79+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
7980
- name: Log in to the Container registry
80-
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
81+
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
8182
with:
8283
registry: ${{ env.REGISTRY }}
8384
username: ${{ secrets.TCR_USERNAME }}
8485
password: ${{ secrets.TCR_TOKEN }}
86+
87+
- name: Set Version/Commit
88+
run: |
89+
source ./scripts/version
90+
echo "VERSION=${VERSION}" >> $GITHUB_ENV
91+
echo "COMMIT=${COMMIT}" >> $GITHUB_ENV
92+
8593
- name: Build and push the webhook image
8694
id: build
87-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
95+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
8896
with:
8997
context: .
9098
file: ./package/Dockerfile
99+
secrets: |
100+
token=${{ secrets.RD_ONLY_GH_TOKEN }}
91101
platforms: "linux/${{ matrix.arch }}"
92102
outputs: type=image,name=${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook,push-by-digest=true,name-canonical=true,push=true
103+
build-args: |
104+
VERSION=${{ env.VERSION }}
105+
COMMIT=${{ env.COMMIT }}
106+
GOPRIVATE=github.com/cnrancher
107+
93108
- name: Export digest
94109
run: |
95110
mkdir -p /tmp/digests
@@ -115,16 +130,16 @@ jobs:
115130
pattern: digests-*
116131
merge-multiple: true
117132
- name: Set up Docker Buildx
118-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
119-
# PANDARIA
133+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
120134
# - name: "Read vault secrets"
121-
# uses: rancher-eio/read-vault-secrets@main
135+
# uses: rancher-eio/read-vault-secrets@0da85151ad1f19ed7986c41587e45aac1ace74b6 # v3
122136
# with:
123137
# secrets: |
124138
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
125139
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
140+
126141
- name: Log in to the Container registry
127-
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
142+
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
128143
with:
129144
registry: ${{ env.REGISTRY }}
130145
username: ${{ secrets.TCR_USERNAME }}

.github/workflows/release.yaml

Lines changed: 25 additions & 56 deletions
Original file line numberDiff line numberDiff line change
@@ -26,16 +26,9 @@ jobs:
2626
steps:
2727

2828
- name : Checkout repository
29-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
30-
# https://github.com/actions/checkout/releases/tag/v4.1.1
29+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
3130

32-
- name: Setup Go
33-
uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0
34-
# https://github.com/actions/setup-go/releases/tag/v5.0.0
35-
with:
36-
go-version-file: 'go.mod'
37-
38-
- name: Build and package
31+
- name: Build Binary
3932
run: |
4033
./scripts/build
4134
mkdir -p dist/artifacts
@@ -44,9 +37,8 @@ jobs:
4437
ARCH: "${{ matrix.arch}}"
4538
GOARCH: "${{ matrix.arch}}"
4639

47-
- name: Generate checksum files
40+
- name: Prepare Artifacts
4841
run: |
49-
ls -lR dist
5042
cd dist/artifacts
5143
sha256sum webhook-linux-${{ matrix.arch }} > sha256sum-${{ matrix.arch }}.txt
5244
@@ -67,10 +59,10 @@ jobs:
6759

6860
- name : Checkout repository
6961
# https://github.com/actions/checkout/releases/tag/v4.1.1
70-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
62+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
7163

7264
- name: package-helm
73-
run: ./scripts/package-helm
65+
run: make package-helm
7466

7567
- name: Download the amd64 artifacts
7668
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
@@ -113,71 +105,61 @@ jobs:
113105
needs: build
114106
steps:
115107
- name : Checkout repository
116-
# https://github.com/actions/checkout/releases/tag/v4.1.1
117-
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
118-
108+
uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
119109
- name: Download the artifacts
120110
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
121-
# https://github.com/actions/download-artifact/releases/tag/v4.1.7
122111
with:
123112
name: webhook-artifacts-${{ matrix.arch }}
124113
path: dist/artifacts
125-
126114
- name: Move binary to bin/
127115
run: |
128116
mkdir -p bin/
129117
cp -v dist/artifacts/webhook-linux-${{ matrix.arch }} bin/webhook
130118
chmod +x bin/webhook
131119
132-
# PANDARIA
133-
# - name: "Read vault secrets"
134-
# uses: rancher-eio/read-vault-secrets@main
135-
# with:
136-
# secrets: |
137-
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
138-
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
139-
140120
- name: Set up QEMU
141-
# https://github.com/docker/setup-qemu-action/releases/tag/v3.1.0
142-
uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3.6.0
143-
121+
uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
144122
- name: Set up Docker Buildx
145-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
146-
# https://github.com/docker/setup-buildx-action/releases/tag/v3.4.0
147-
123+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
148124
- name: Log in to the Container registry
149-
# https://github.com/docker/login-action/releases/tag/v3.2.0
150-
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
125+
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
151126
with:
152127
registry: ${{ env.REGISTRY }}
153128
username: ${{ secrets.TCR_USERNAME }}
154129
password: ${{ secrets.TCR_TOKEN }}
155130

131+
- name: Set Version/Commit
132+
run: |
133+
source ./scripts/version
134+
echo "VERSION=${VERSION}" >> $GITHUB_ENV
135+
echo "COMMIT=${COMMIT}" >> $GITHUB_ENV
136+
156137
- name: Build and push the webhook image
157-
id: build
158-
# https://github.com/docker/build-push-action/releases/tag/v6.3.0
159-
uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0
138+
uses: docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6.19.2
160139
with:
161140
context: .
162141
file: ./package/Dockerfile
142+
secrets: |
143+
token=${{ secrets.RD_ONLY_GH_TOKEN }}
163144
platforms: "linux/${{ matrix.arch }}"
164145
outputs: type=image,name=${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook,push-by-digest=true,name-canonical=true,push=true
146+
build-args: |
147+
VERSION=${{ env.VERSION }}
148+
COMMIT=${{ env.COMMIT }}
149+
GOPRIVATE=github.com/cnrancher
165150
166151
- name: Export digest
167152
run: |
168153
mkdir -p /tmp/digests
169154
digest="${{ steps.build.outputs.digest }}"
170155
touch "/tmp/digests/${digest#sha256:}"
171-
172156
- name: Upload digest
173157
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
174-
# https://github.com/actions/upload-artifact/releases/tag/v4.3.3
175158
with:
176159
name: digests-${{ matrix.arch }}
177160
path: /tmp/digests/*
178161
if-no-files-found: error
179162
retention-days: 1
180-
181163
merge:
182164
permissions:
183165
id-token: write
@@ -186,33 +168,19 @@ jobs:
186168
steps:
187169
- name: Download digests
188170
uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
189-
# https://github.com/actions/download-artifact/releases/tag/v4.1.7
190171
with:
191172
path: /tmp/digests
192173
pattern: digests-*
193174
merge-multiple: true
194-
195175
- name: Set up Docker Buildx
196-
uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1
197-
# https://github.com/docker/setup-buildx-action/releases/tag/v3.4.0
198-
199-
# PANDARIA
200-
# - name: "Read vault secrets"
201-
# uses: rancher-eio/read-vault-secrets@main
202-
# with:
203-
# secrets: |
204-
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials username | DOCKER_USERNAME ;
205-
# secret/data/github/repo/${{ github.repository }}/dockerhub/rancher/credentials password | DOCKER_PASSWORD
176+
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
206177

207178
- name: Log in to the Container registry
208-
uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0
209-
# https://github.com/docker/login-action/releases/tag/v3.2.0
179+
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
210180
with:
211181
registry: ${{ env.REGISTRY }}
212182
username: ${{ secrets.TCR_USERNAME }}
213183
password: ${{ secrets.TCR_TOKEN }}
214-
215-
# setup tag name
216184
- if: ${{ startsWith(github.ref, 'refs/tags/') }}
217185
run: |
218186
echo TAG_NAME=$(echo $GITHUB_REF | sed -e "s|refs/tags/||") >> $GITHUB_ENV
@@ -222,6 +190,7 @@ jobs:
222190
run: |
223191
docker buildx imagetools create -t ${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook:${{ env.TAG_NAME }} \
224192
$(printf '${{ env.REGISTRY }}/${{ env.REPO }}/rancher-webhook@sha256:%s ' *)
193+
225194
image-sign:
226195
permissions:
227196
contents: read

0 commit comments

Comments
 (0)