From 8d3185f8abceb86fed0ccfa262e5aa972c24fe33 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Tue, 6 Oct 2026 16:31:48 +0200 Subject: [PATCH] fix(ci): install jq for deploy validation regressions --- .gitea/tests/deploy-validation.sh | 4 ++-- .gitea/workflows/ci.yaml | 2 +- .gitea/workflows/install-ci-tools.sh | 10 ++++++++++ .gitea/workflows/tool-versions.env | 3 +++ 4 files changed, 16 insertions(+), 3 deletions(-) diff --git a/.gitea/tests/deploy-validation.sh b/.gitea/tests/deploy-validation.sh index b03a429..94e6480 100755 --- a/.gitea/tests/deploy-validation.sh +++ b/.gitea/tests/deploy-validation.sh @@ -29,7 +29,7 @@ if validate_compose_file "$scratch/compose.yaml" >"$scratch/config.log" 2>&1; th echo 'Full Compose validation accepted a missing variable' >&2 exit 1 fi -rg -q 'required for this regression' "$scratch/config.log" +grep -q 'required for this regression' "$scratch/config.log" HOMELAB_TEST_REQUIRED=present validate_compose_file "$scratch/compose.yaml" cat >"$scratch/resources.json" <<'JSON' @@ -70,7 +70,7 @@ if check_referenced_secrets >"$scratch/secrets.log"; then echo 'Namespace-scoped Secret check accepted a missing Secret' >&2 exit 1 fi -rg -q 'MISSING OR UNREADABLE: app/credentials' "$scratch/secrets.log" +grep -q 'MISSING OR UNREADABLE: app/credentials' "$scratch/secrets.log" # API/rendering errors must not produce an empty reference list and pass. kubectl() { return 1; } if check_referenced_secrets >"$scratch/secrets.log"; then diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index 232534d..b9f7ebc 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -88,7 +88,7 @@ jobs: shell: bash run: | set -euo pipefail - tools_dir="$(bash .gitea/workflows/install-ci-tools.sh shellcheck)" + tools_dir="$(bash .gitea/workflows/install-ci-tools.sh shellcheck jq)" export PATH="$tools_dir:$PATH" mapfile -t scripts < <( git ls-files '*.sh' ':(glob)**/*.bash' diff --git a/.gitea/workflows/install-ci-tools.sh b/.gitea/workflows/install-ci-tools.sh index 988fe64..2fcb3b3 100755 --- a/.gitea/workflows/install-ci-tools.sh +++ b/.gitea/workflows/install-ci-tools.sh @@ -120,6 +120,15 @@ install_shellcheck() { rm -rf "$tmp" } +install_jq() { + if at_version jq "${JQ_VERSION}"; then + return 0 + fi + fetch "https://github.com/jqlang/jq/releases/download/jq-${JQ_VERSION}/jq-linux-${goarch}" \ + "$BIN_DIR/jq" + chmod 0755 "$BIN_DIR/jq" +} + install_uv() { if at_version uv "${UV_VERSION}"; then return 0 @@ -236,6 +245,7 @@ for tool in "${wanted[@]}"; do case "$tool" in kubeconform) install_kubeconform ;; shellcheck) install_shellcheck ;; + jq) install_jq ;; actionlint) install_actionlint ;; prettier) install_prettier ;; ruff) install_ruff ;; diff --git a/.gitea/workflows/tool-versions.env b/.gitea/workflows/tool-versions.env index d010495..cf8edb9 100644 --- a/.gitea/workflows/tool-versions.env +++ b/.gitea/workflows/tool-versions.env @@ -31,3 +31,6 @@ UV_VERSION="0.12.17" # so the tree that gets tested is the tree that gets built. Renovate keeps this # in step with the Dockerfile's node: tag via the "node runtime" group. NODE_VERSION="22.23.3" + +# Secret-reference regression tests parse rendered Kubernetes objects. +JQ_VERSION="1.8.1"