fix(deploy): validate compose without workstation secrets
deploy / validate (push) Skipped
renovate-ci / validate-renovate (push) Skipped
ci / lint-prettier (push) Successful in 2s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 1s
ci / validate (push) Successful in 2s
ci / build (push) Skipped

docker compose config required real values for gitignored .env files and secrets, so validate always failed on stacks with :? guards (netbird, netbox). Validate structure only via --no-interpolate, --no-env-resolution and --no-path-resolution, keeping normalization and consistency checks.
This commit is contained in:
forust committed 2026-09-26 17:00:43 +02:00
1 parent 27ab6b859e
commit a2ff9515a3
1 file changed
+18 -1
+18 -1
View File
@@ -89,10 +89,27 @@ stage_validate() {
cd "$REPO"
select_manifests
local m k cf
# Compose .env files and secret files are gitignored by design, so the
# workstation never has real values for them. Validate structure only:
# skip interpolation, env-file resolution, and path resolution so that
# required-variable guards (:?) and missing local files don't fail CI.
# Normalization and consistency checks stay enabled.
local compose_validate_flags=()
local compose_config_help
compose_config_help="$(docker compose config --help 2>/dev/null || true)"
if printf '%s' "$compose_config_help" | grep -q -- '--no-interpolate'; then
compose_validate_flags+=(--no-interpolate)
fi
if printf '%s' "$compose_config_help" | grep -q -- '--no-env-resolution'; then
compose_validate_flags+=(--no-env-resolution)
fi
if printf '%s' "$compose_config_help" | grep -q -- '--no-path-resolution'; then
compose_validate_flags+=(--no-path-resolution)
fi
log "Validate compose stacks"
for cf in ${COMPOSE_STACKS[@]+"${COMPOSE_STACKS[@]}"}; do
echo " config: $cf"
docker compose -f "$cf" config --quiet
docker compose -f "$cf" config --quiet "${compose_validate_flags[@]}"
done
log "Validate k8s manifests (kubectl dry-run=client)"
for m in ${K8S_MANIFESTS[@]+"${K8S_MANIFESTS[@]}"}; do