fddd82704fd3e0bd2312ba92843c9f8c13dcb6ee
`kubectl apply --dry-run=server` persists nothing, but it does execute the admission webhooks of the real API server. The validate job runs on pull_request with no branch guard, so anyone able to open a PR could run arbitrary manifest content through cert-manager and Traefik in production. Limit the step to pushes to main. A pull request loses nothing by it: only main is ever deployed, and this job has to complete successfully before the deploy workflow is allowed to start, so a bad CRD is still caught before anything reaches the cluster -- on the push instead of on the PR. The skip is announced rather than silent, so a missing server-side pass does not read as a pass. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
Collection of my self-hosted instruments and apps
https://forust.xyz
2.8 MiB
0 Stars
0 Watchers
0 Forks
Languages
HTML
38.6%
Python
34.5%
Shell
24.9%
CSS
1.1%
Go Template
0.5%
Other
0.4%