Files
auricom-home-cluster/.github/workflows/kubeconform.yaml
feisar-bot f057f3a79b ⬆️ Update tibdex/github-app-token action to v2.1.0
| datasource  | package                 | from   | to     |
| ----------- | ----------------------- | ------ | ------ |
| github-tags | tibdex/github-app-token | v2.0.0 | v2.1.0 |
2023-09-19 16:22:27 +00:00

48 lines
1.3 KiB
YAML

---
name: "Kubeconform"
on:
workflow_dispatch:
pull_request:
branches: ["main"]
paths: ["kubernetes/**"]
env:
KUBERNETES_DIR: ./kubernetes
SCHEMA_DIR: /home/runner/.datree/crdSchemas
jobs:
kubeconform:
name: Kubeconform
runs-on: ubuntu-latest
steps:
- name: Generate Token
uses: tibdex/github-app-token@3beb63f4bd073e61482598c45c71c1019b59b73a # v2.1.0
id: generate-token
with:
app_id: "${{ secrets.BOT_APP_ID }}"
private_key: "${{ secrets.BOT_APP_PRIVATE_KEY }}"
- name: Checkout
uses: actions/checkout@3df4ab11eba7bda6032a0b82a6bb43b11571feac # v4.0.0
with:
token: "${{ steps.generate-token.outputs.token }}"
- name: Setup Homebrew
uses: Homebrew/actions/setup-homebrew@master
- name: Setup Tools
shell: bash
run: brew install fluxcd/tap/flux kubeconform kustomize
- name: Download CRDs
shell: bash
run: |
mkdir -p ${{ env.SCHEMA_DIR }}
flux pull artifact oci://ghcr.io/auricom/manifests/kubernetes-schemas:latest \
--output=${{ env.SCHEMA_DIR }}
- name: Run kubeconform
shell: bash
run: bash ./.github/scripts/kubeconform.sh ${{ env.KUBERNETES_DIR }} ${{ env.SCHEMA_DIR }}