Bump oras-go, x/crypto, and Go toolchain (#5433) #1338
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Upgrade fleet in latest Rancher to dev version and run MC tests | |
| name: E2E Upgrade Fleet in Rancher To HEAD | |
| on: | |
| schedule: | |
| # Run everyday day at 1:00 PM | |
| - cron: '0 13 * * *' | |
| workflow_dispatch: | |
| inputs: | |
| ref: | |
| description: "checkout git branch/tag" | |
| required: true | |
| default: "main" | |
| push: | |
| tags: [ 'v*' ] | |
| paths-ignore: | |
| - '*.md' | |
| env: | |
| GOARCH: amd64 | |
| CGO_ENABLED: 0 | |
| SETUP_K3S_VERSION: 'v1.33.1-k3s1' | |
| jobs: | |
| rancher-fleet-integration: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| ref: ${{ github.event.inputs.ref }} | |
| - | |
| uses: actions/setup-go@4b73464bb391d4059bd26b0524d20df3927bd417 # v6.3.0 | |
| with: | |
| go-version-file: 'go.mod' | |
| - | |
| name: Install Ginkgo CLI | |
| run: go install github.com/onsi/ginkgo/v2/ginkgo | |
| - | |
| name: Cache crust-gather CLI | |
| id: cache-crust | |
| uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3 | |
| with: | |
| path: ~/.local/bin/crust-gather | |
| key: ${{ runner.os }}-crust-gather-${{ hashFiles('.github/scripts/install-crust-gather.sh') }} | |
| restore-keys: | | |
| ${{ runner.os }}-crust-gather- | |
| - | |
| name: Install crust-gather CLI | |
| run: | | |
| if [ "${{ steps.cache-crust.outputs.cache-hit }}" != "true" ]; then | |
| ./.github/scripts/install-crust-gather.sh | |
| else | |
| echo "Using cached crust-gather CLI" | |
| chmod +x ~/.local/bin/crust-gather | |
| fi | |
| echo "$HOME/.local/bin" >> "$GITHUB_PATH" | |
| - | |
| uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3 | |
| id: rancher-cli-cache | |
| with: | |
| path: /home/runner/.local/bin | |
| key: ${{ runner.os }}-rancher-cli-2.6.0 | |
| - | |
| name: Install Rancher CLI | |
| if: steps.rancher-cli-cache.outputs.cache-hit != 'true' | |
| run: | | |
| # download an older CLI to avoid https://github.com/rancher/rancher/issues/37574 | |
| mkdir -p /home/runner/.local/bin | |
| wget -q https://github.com/rancher/cli/releases/download/v2.6.0/rancher-linux-amd64-v2.6.0.tar.gz | |
| tar -xz --strip-components=2 -f rancher-linux-amd64-v2.6.0.tar.gz -C /home/runner/.local/bin | |
| rancher --version | |
| - | |
| name: Build fleet binaries | |
| run: | | |
| ./.github/scripts/build-fleet-binaries.sh | |
| - | |
| name: Set up QEMU | |
| uses: docker/setup-qemu-action@29109295f81e9208d7d86ff1c6c12d2833863392 # v3 | |
| - | |
| name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3 | |
| - | |
| name: Get uuid | |
| id: uuid | |
| run: echo "::set-output name=uuid::$(uuidgen)" | |
| - | |
| id: meta-fleet | |
| uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f # v5 | |
| with: | |
| images: | | |
| ttl.sh/rancher/fleet-${{ steps.uuid.outputs.uuid }} | |
| tags: type=raw,value=1h | |
| - | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6 | |
| with: | |
| context: . | |
| file: package/Dockerfile | |
| build-args: | | |
| ARCH=${{ env.GOARCH }} | |
| push: true | |
| tags: ${{ steps.meta-fleet.outputs.tags }} | |
| labels: ${{ steps.meta-fleet.outputs.labels }} | |
| - | |
| id: meta-fleet-agent | |
| uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f # v5 | |
| with: | |
| images: | | |
| ttl.sh/rancher/fleet-agent-${{ steps.uuid.outputs.uuid }} | |
| tags: type=raw,value=1h | |
| - | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6 | |
| with: | |
| context: . | |
| file: package/Dockerfile.agent | |
| build-args: | | |
| ARCH=${{ env.GOARCH }} | |
| push: true | |
| tags: ${{ steps.meta-fleet-agent.outputs.tags }} | |
| labels: ${{ steps.meta-fleet-agent.outputs.labels }} | |
| - | |
| name: Cache k3d CLI | |
| id: cache-k3d | |
| uses: actions/cache@cdf6c1fa76f9f475f3d7449005a359c84ca0f306 # v5.0.3 | |
| with: | |
| path: ~/.local/bin/k3d | |
| key: ${{ runner.os }}-k3d-${{ hashFiles('.github/scripts/install-k3d.sh') }} | |
| restore-keys: | | |
| ${{ runner.os }}-k3d- | |
| - | |
| name: Install k3d | |
| run: | | |
| if [ "${{ steps.cache-k3d.outputs.cache-hit }}" != "true" ]; then | |
| ./.github/scripts/install-k3d.sh | |
| else | |
| echo "Using cached k3d" | |
| chmod +x ~/.local/bin/k3d | |
| fi | |
| - | |
| name: Set up k3d control-plane cluster | |
| run: | | |
| k3d cluster create upstream --wait \ | |
| -p "80:80@agent:0:direct" \ | |
| -p "443:443@agent:0:direct" \ | |
| --api-port 6443 \ | |
| --agents 1 \ | |
| --k3s-arg '--kubelet-arg=eviction-hard=imagefs.available<1%,nodefs.available<1%@agent:*' \ | |
| --k3s-arg '--kubelet-arg=eviction-minimum-reclaim=imagefs.available=1%,nodefs.available=1%@agent:*' \ | |
| --network "nw01" \ | |
| --image docker.io/rancher/k3s:${{ env.SETUP_K3S_VERSION }} | |
| - | |
| name: Set up k3d downstream cluster | |
| run: | | |
| k3d cluster create downstream --wait \ | |
| -p "81:80@agent:0:direct" \ | |
| -p "444:443@agent:0:direct" \ | |
| --api-port 6644 \ | |
| --agents 1 \ | |
| --k3s-arg '--kubelet-arg=eviction-hard=imagefs.available<1%,nodefs.available<1%@agent:*' \ | |
| --k3s-arg '--kubelet-arg=eviction-minimum-reclaim=imagefs.available=1%,nodefs.available=1%@agent:*' \ | |
| --network "nw01" \ | |
| --image docker.io/rancher/k3s:${{ env.SETUP_K3S_VERSION }} | |
| - | |
| name: Set up latest Rancher | |
| env: | |
| public_hostname: "172.18.0.1.sslip.io" | |
| run: | | |
| ./.github/scripts/setup-latest-rancher.sh | |
| - | |
| name: Register Rancher's downstream clusters | |
| env: | |
| public_hostname: "172.18.0.1.sslip.io" | |
| run: | | |
| ./.github/scripts/wait-for-loadbalancer.sh | |
| ./.github/scripts/register-downstream-clusters.sh | |
| # wait for cluster to settle | |
| sleep 30 | |
| ./.github/scripts/label-downstream-cluster.sh | |
| - | |
| name: Create example workload | |
| run: | | |
| kubectl apply -n fleet-local -f e2e/assets/fleet-upgrade/gitrepo-simple.yaml | |
| kubectl apply -n fleet-default -f e2e/assets/fleet-upgrade/gitrepo-simple.yaml | |
| # wait for bundle ready | |
| until kubectl get bundles -n fleet-local test-simple-simple-chart -o=jsonpath='{.status.conditions[?(@.type=="Ready")].status}' | grep -q "True"; do sleep 3; done | |
| until kubectl get bundles -n fleet-default test-simple-simple-chart -o=jsonpath='{.status.conditions[?(@.type=="Ready")].status}' | grep -q "True"; do sleep 3; done | |
| - | |
| name: Deploy development fleet | |
| run: | | |
| echo "${{ steps.meta-fleet.outputs.tags }} ${{ steps.meta-fleet-agent.outputs.tags }}" | |
| ./.github/scripts/upgrade-rancher-fleet-to-dev-fleet.sh ${{ steps.meta-fleet.outputs.tags }} ${{ steps.meta-fleet-agent.outputs.tags }} | |
| - | |
| name: E2E tests for examples | |
| env: | |
| FLEET_E2E_NS: fleet-local | |
| FLEET_E2E_NS_DOWNSTREAM: fleet-default | |
| run: | | |
| kubectl config use-context k3d-upstream | |
| export CI_REGISTERED_CLUSTER=$(kubectl get clusters.fleet.cattle.io -n $FLEET_E2E_NS_DOWNSTREAM -o jsonpath='{..name}') | |
| ginkgo --github-output e2e/multi-cluster | |
| - | |
| name: Dump Failed Downstream Environment | |
| if: failure() | |
| run: | | |
| kubectl config use-context k3d-downstream | |
| crust-gather collect --exclude-namespace=kube-system --exclude-kind=Lease --duration=5s -f tmp/downstream | |
| - | |
| name: Upload logs | |
| uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 | |
| if: failure() | |
| with: | |
| name: gha-fleet-rancher-logs-${{ github.sha }}-${{ github.run_id }} | |
| path: | | |
| tmp/downstream | |
| tmp/upstream | |
| retention-days: 2 |