Merge pull request 'fix(deploy): reject unsafe per-file pruning' (#85) from fix/deploy-prune-guard into main
renovate-ci / validate-renovate (push) Successful in 9s
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 11s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 8s
ci / build (push) Successful in 23s
renovate-ci / validate-renovate (push) Successful in 9s
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 4s
ci / lint-shellcheck (push) Successful in 11s
ci / lint-prettier (push) Successful in 15s
ci / lint-ruff (push) Successful in 5s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 8s
ci / build (push) Successful in 23s
Reviewed-on: #85
This commit was merged in pull request #85.
This commit is contained in:
commit
88705fec88
1 file changed
+14
-5
@@ -31,6 +31,16 @@ warn() {
|
||||
echo "WARNING: $*" >&2
|
||||
}
|
||||
|
||||
# Prune needs the complete desired set in one invocation. Per-file pruning
|
||||
# treats resources from the other files as absent and can delete them.
|
||||
check_prune_mode() {
|
||||
if [ "$APPLY_PRUNE" = "true" ]; then
|
||||
echo "ERROR: APPLY_PRUNE=true is unsupported by the per-file deploy loop." >&2
|
||||
echo "Disable it; remove obsolete resources explicitly after review." >&2
|
||||
return 1
|
||||
fi
|
||||
}
|
||||
|
||||
collect_k8s() {
|
||||
git -C "$REPO" ls-files -- "$1" \
|
||||
| grep -E '\.ya?ml$' \
|
||||
@@ -720,6 +730,7 @@ check_referenced_secrets() {
|
||||
}
|
||||
|
||||
stage_validate() {
|
||||
check_prune_mode || return 1
|
||||
cd "$REPO"
|
||||
select_manifests
|
||||
local m k cf
|
||||
@@ -753,18 +764,16 @@ stage_validate() {
|
||||
}
|
||||
|
||||
stage_apply_k8s() {
|
||||
check_prune_mode || return 1
|
||||
cd "$REPO"
|
||||
select_manifests >/dev/null
|
||||
local ns_files=() other_files=() m k prune_opts=()
|
||||
local ns_files=() other_files=() m k
|
||||
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do
|
||||
case "$m" in
|
||||
*/namespace.y?ml) ns_files+=("$m") ;;
|
||||
*) other_files+=("$m") ;;
|
||||
esac
|
||||
done
|
||||
if [ "$APPLY_PRUNE" = "true" ]; then
|
||||
prune_opts=(--prune -l app.kubernetes.io/managed-by=homelab-deploy)
|
||||
fi
|
||||
|
||||
# Record what is about to change, and publish it for the verify job, before
|
||||
# the first apply. Both are fatal on failure: see snapshot_dir.
|
||||
@@ -789,7 +798,7 @@ stage_apply_k8s() {
|
||||
if [ "${#other_files[@]}" -gt 0 ]; then
|
||||
log "Applying resources (${#other_files[@]} files, our images pinned to digests)"
|
||||
for m in "${other_files[@]}"; do
|
||||
if ! render_pinned <"$m" | kubectl apply "${prune_opts[@]}" -f -; then
|
||||
if ! render_pinned <"$m" | kubectl apply -f -; then
|
||||
echo "ERROR: apply failed for ${m#"$REPO"/}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
Reference in new issue
Block a user