ci: run all lint jobs natively without docker
This commit is contained in:
1 parent
c9e6fc0e2b
commit
51677ae184
1 file changed
+3
-22
@@ -7,7 +7,6 @@ on:
|
|||||||
pull_request:
|
pull_request:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
# Fast pushes on a branch cancel superseded runs; main is never cancelled.
|
|
||||||
concurrency:
|
concurrency:
|
||||||
group: ci-${{ github.ref }}
|
group: ci-${{ github.ref }}
|
||||||
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
|
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
|
||||||
@@ -36,13 +35,7 @@ jobs:
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
docker run --rm \
|
prettier --check --ignore-unknown "${prettier_files[@]}"
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
`# $HOME persists on self-hosted runners: seed npm cache once, skip the tarball download after that.` \
|
|
||||||
-v "$HOME/.npm:/root/.npm" \
|
|
||||||
node:22-alpine \
|
|
||||||
sh -lc 'npx --yes prettier@3.9.8 --check --ignore-unknown "$@"' sh "${prettier_files[@]}"
|
|
||||||
|
|
||||||
lint-ruff:
|
lint-ruff:
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
@@ -53,7 +46,6 @@ jobs:
|
|||||||
- name: Lint Python with Ruff
|
- name: Lint Python with Ruff
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
# Native: ruff ships in Arch repos, no container pull needed.
|
|
||||||
ruff check .
|
ruff check .
|
||||||
|
|
||||||
lint-yaml:
|
lint-yaml:
|
||||||
@@ -76,7 +68,6 @@ jobs:
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Native: yamllint ships in Arch repos, no container pull needed.
|
|
||||||
yamllint -c .yamllint "${yaml_files[@]}"
|
yamllint -c .yamllint "${yaml_files[@]}"
|
||||||
|
|
||||||
lint-dockerfiles:
|
lint-dockerfiles:
|
||||||
@@ -88,7 +79,6 @@ jobs:
|
|||||||
- name: Lint Dockerfiles
|
- name: Lint Dockerfiles
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
# Stays in Docker: hadolint is AUR-only on Arch, container keeps the pin hermetic.
|
|
||||||
mapfile -t dockerfiles < <(
|
mapfile -t dockerfiles < <(
|
||||||
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
git ls-files ':(glob)**/Dockerfile' ':(glob)**/Dockerfile.*'
|
||||||
)
|
)
|
||||||
@@ -98,12 +88,7 @@ jobs:
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
docker run --rm \
|
hadolint -c .hadolint.yaml "${dockerfiles[@]}"
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
--entrypoint hadolint \
|
|
||||||
hadolint/hadolint:latest-debian \
|
|
||||||
-c .hadolint.yaml "${dockerfiles[@]}"
|
|
||||||
|
|
||||||
validate:
|
validate:
|
||||||
runs-on: [self-hosted, linux, arch, homelab]
|
runs-on: [self-hosted, linux, arch, homelab]
|
||||||
@@ -114,7 +99,6 @@ jobs:
|
|||||||
- name: Validate Kubernetes manifests
|
- name: Validate Kubernetes manifests
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
# Stays in Docker: avoids a manual `pacman -S kubeconform` on every runner, pin stays hermetic.
|
|
||||||
mapfile -t manifests < <(
|
mapfile -t manifests < <(
|
||||||
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
git ls-files ':(glob)**/k8s/**/*.yaml' ':(glob)**/k8s/**/*.yml' \
|
||||||
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
| grep -Ev '(^|/)(kustomization\.ya?ml|.*\.example\.ya?ml|.*values\.ya?ml|patch-.*\.ya?ml)$'
|
||||||
@@ -125,10 +109,7 @@ jobs:
|
|||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
|
|
||||||
docker run --rm \
|
kubeconform \
|
||||||
-v "$PWD:/work" \
|
|
||||||
-w /work \
|
|
||||||
ghcr.io/yannh/kubeconform:latest \
|
|
||||||
-strict \
|
-strict \
|
||||||
-ignore-missing-schemas \
|
-ignore-missing-schemas \
|
||||||
-summary \
|
-summary \
|
||||||
|
|||||||
Reference in new issue
Block a user