From a2ff9515a39753481dd867d8eafb2dbc6be91c52 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Sat, 26 Sep 2026 17:00:43 +0200 Subject: [PATCH] fix(deploy): validate compose without workstation secrets docker compose config required real values for gitignored .env files and secrets, so validate always failed on stacks with :? guards (netbird, netbox). Validate structure only via --no-interpolate, --no-env-resolution and --no-path-resolution, keeping normalization and consistency checks. --- .gitea/workflows/deploy-lib.sh | 19 ++++++++++++++++++- 1 file changed, 18 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/deploy-lib.sh b/.gitea/workflows/deploy-lib.sh index d6a5853..4e9013b 100644 --- a/.gitea/workflows/deploy-lib.sh +++ b/.gitea/workflows/deploy-lib.sh @@ -89,10 +89,27 @@ stage_validate() { cd "$REPO" select_manifests local m k cf + # Compose .env files and secret files are gitignored by design, so the + # workstation never has real values for them. Validate structure only: + # skip interpolation, env-file resolution, and path resolution so that + # required-variable guards (:?) and missing local files don't fail CI. + # Normalization and consistency checks stay enabled. + local compose_validate_flags=() + local compose_config_help + compose_config_help="$(docker compose config --help 2>/dev/null || true)" + if printf '%s' "$compose_config_help" | grep -q -- '--no-interpolate'; then + compose_validate_flags+=(--no-interpolate) + fi + if printf '%s' "$compose_config_help" | grep -q -- '--no-env-resolution'; then + compose_validate_flags+=(--no-env-resolution) + fi + if printf '%s' "$compose_config_help" | grep -q -- '--no-path-resolution'; then + compose_validate_flags+=(--no-path-resolution) + fi log "Validate compose stacks" for cf in ${COMPOSE_STACKS[@]+"${COMPOSE_STACKS[@]}"}; do echo " config: $cf" - docker compose -f "$cf" config --quiet + docker compose -f "$cf" config --quiet "${compose_validate_flags[@]}" done log "Validate k8s manifests (kubectl dry-run=client)" for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do