c5171cf014
Bumps the github-actions group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.12.1` | `2.13.0` | | [github/codeql-action](https://github.com/github/codeql-action) | `3.29.0` | `3.29.8` | | [docker/login-action](https://github.com/docker/login-action) | `3.4.0` | `3.5.0` | | [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) | `3.8.2` | `3.9.2` | | [anchore/sbom-action](https://github.com/anchore/sbom-action) | `0.20.1` | `0.20.4` | | [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) | `0.31.0` | `0.32.0` | | [slsa-framework/slsa-verifier](https://github.com/slsa-framework/slsa-verifier) | `2.7.0` | `2.7.1` | Updates `step-security/harden-runner` from 2.12.1 to 2.13.0 - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](https://github.com/step-security/harden-runner/compare/002fdce3c6a235733a90a27c80493a3241e56863...ec9f2d5744a09debf3a187a3f4f675c53b671911) Updates `github/codeql-action` from 3.29.0 to 3.29.8 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/ce28f5bb42b7a9f2c824e633a3f6ee835bab6858...76621b61decf072c1cee8dd1ce2d2a82d33c17ed) Updates `docker/login-action` from 3.4.0 to 3.5.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/74a5d142397b4f367a81961eba4e8cd7edddf772...184bdaa0721073962dff0199f1fb9940f07167d1) Updates `sigstore/cosign-installer` from 3.8.2 to 3.9.2 - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](https://github.com/sigstore/cosign-installer/compare/3454372f43399081ed03b604cb2d021dabca52bb...d58896d6a1865668819e1d91763c7751a165e159) Updates `anchore/sbom-action` from 0.20.1 to 0.20.4 - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](https://github.com/anchore/sbom-action/compare/9246b90769f852b3a8921f330c59e0b3f439d6e9...7b36ad622f042cab6f59a75c2ac24ccb256e9b45) Updates `aquasecurity/trivy-action` from 0.31.0 to 0.32.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](https://github.com/aquasecurity/trivy-action/compare/76071ef0d7ec797419534a183b498b4d6366cf37...dc5a429b52fcf669ce959baa2c2dd26090d2a6c4) Updates `slsa-framework/slsa-verifier` from 2.7.0 to 2.7.1 - [Release notes](https://github.com/slsa-framework/slsa-verifier/releases) - [Changelog](https://github.com/slsa-framework/slsa-verifier/blob/main/RELEASE.md) - [Commits](https://github.com/slsa-framework/slsa-verifier/compare/6657aada084353c65e5dde35394b1a010289fab0...ea584f4502babc6f60d9bc799dbbb13c1caa9ee6) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: github/codeql-action dependency-version: 3.29.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: docker/login-action dependency-version: 3.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: sigstore/cosign-installer dependency-version: 3.9.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: anchore/sbom-action dependency-version: 0.20.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: aquasecurity/trivy-action dependency-version: 0.32.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: slsa-framework/slsa-verifier dependency-version: 2.7.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
333 lines
10 KiB
YAML
333 lines
10 KiB
YAML
name: Fission CI
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
- '!dependabot/**'
|
|
paths:
|
|
- "**.go"
|
|
- "charts/**"
|
|
- "test/**"
|
|
- go.mod
|
|
- go.sum
|
|
pull_request:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- "**.go"
|
|
- "charts/**"
|
|
- "test/**"
|
|
- go.mod
|
|
- go.sum
|
|
|
|
env:
|
|
HELM_VERSION: v3.16.4
|
|
KIND_VERSION: v0.26.0
|
|
KIND_CLUSTER_NAME: kind
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: fission-ci-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
# Job to run change detection
|
|
integration-test:
|
|
runs-on: ${{ matrix.os }}
|
|
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-ci') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
kindversion: ["v1.28.15", "v1.30.8", "v1.32.0"]
|
|
os: [ubuntu-24.04]
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout sources
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
|
|
|
- name: setup go
|
|
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
|
|
with:
|
|
go-version-file: "go.mod"
|
|
cache: true
|
|
|
|
- name: Checkout sources
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
|
with:
|
|
repository: fission/examples
|
|
path: examples
|
|
|
|
- name: Helm installation
|
|
uses: Azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 # v4.3.0
|
|
with:
|
|
version: ${{ env.HELM_VERSION }}
|
|
|
|
- name: Kind Cluster
|
|
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
|
|
with:
|
|
node_image: kindest/node:${{ matrix.kindversion }}
|
|
version: ${{ env.KIND_VERSION }}
|
|
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
|
config: kind.yaml
|
|
|
|
- name: Configuring and testing the Installation
|
|
run: |
|
|
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
|
kubectl get nodes
|
|
sudo apt-get install -y apache2-utils
|
|
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
|
kubectl config view
|
|
|
|
- name: Helm chart lint
|
|
run: |
|
|
helm lint charts/fission-all/
|
|
|
|
- name: Install Skaffold
|
|
run: |
|
|
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/v2.14.0/skaffold-linux-amd64
|
|
sudo install skaffold /usr/local/bin/
|
|
skaffold version
|
|
|
|
- name: Install GoReleaser
|
|
uses: goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6.3.0
|
|
with:
|
|
install-only: true
|
|
version: "~> v2"
|
|
|
|
- name: Setup Prometheus Stack
|
|
run: |
|
|
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
|
helm repo update
|
|
kubectl create ns monitoring
|
|
helm install prometheus prometheus-community/kube-prometheus-stack -n monitoring \
|
|
--version 45.28.0 --set grafana.enabled=false --set alertmanager.enabled=false
|
|
|
|
- name: Build and Install Fission CLI
|
|
run: |
|
|
make debug-vars
|
|
make build-fission-cli
|
|
sudo make install-fission-cli
|
|
sudo chmod +x /usr/local/bin/fission
|
|
|
|
- name: Build and Install Fission
|
|
timeout-minutes: 10
|
|
run: |
|
|
kubectl create ns fission
|
|
make create-crds
|
|
SKAFFOLD_PROFILE=kind-ci make skaffold-deploy
|
|
|
|
- name: Port-forward fission components
|
|
run: |
|
|
kubectl port-forward svc/router 8888:80 -nfission &
|
|
|
|
- name: Get fission version
|
|
timeout-minutes: 10
|
|
run: |
|
|
fission version
|
|
|
|
- name: Integration tests
|
|
timeout-minutes: 90
|
|
run: ./test/kind_CI.sh
|
|
|
|
- name: Collect Fission Dump
|
|
timeout-minutes: 5
|
|
if: ${{ always() }}
|
|
run: |
|
|
command -v fission && fission support dump
|
|
|
|
- name: Kind export logs
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
run: |
|
|
kind export logs --name ${{ env.KIND_CLUSTER_NAME }} kind-logs
|
|
|
|
- name: Backup prometheus data
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
run: |
|
|
TRACE=1 ./hack/backup-prometheus.sh
|
|
|
|
- name: Archive fission dump
|
|
timeout-minutes: 10
|
|
if: ${{ failure() || cancelled() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
|
path: fission-dump/*.zip
|
|
retention-days: 5
|
|
|
|
- name: Archive prometheus dump
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: prom-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
|
path: /tmp/prometheus/*
|
|
retention-days: 5
|
|
|
|
- name: Archive kind logs
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
|
path: kind-logs/*
|
|
retention-days: 5
|
|
|
|
# Job to ensure backward compatibility if function and builder pods are created
|
|
# inside functionNamespace and builderNamespace
|
|
integration-test-old:
|
|
runs-on: ${{ matrix.os }}
|
|
if: ${{ contains(github.event.pull_request.labels.*.name, 'run-old-ci') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
kindversion: ["v1.19.16"]
|
|
os: [ubuntu-24.04]
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@ec9f2d5744a09debf3a187a3f4f675c53b671911 # v2.13.0
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: Checkout sources
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
|
|
|
- name: setup go
|
|
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
|
|
with:
|
|
go-version-file: "go.mod"
|
|
cache: true
|
|
|
|
- name: Checkout sources
|
|
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
|
with:
|
|
repository: fission/examples
|
|
path: examples
|
|
|
|
- name: Helm installation
|
|
uses: Azure/setup-helm@b9e51907a09c216f16ebe8536097933489208112 # v4.3.0
|
|
with:
|
|
version: ${{ env.HELM_VERSION }}
|
|
|
|
- name: Kind Cluster
|
|
uses: helm/kind-action@a1b0e391336a6ee6713a0583f8c6240d70863de3 # v1.12.0
|
|
with:
|
|
node_image: kindest/node:${{ matrix.kindversion }}
|
|
version: ${{ env.KIND_VERSION }}
|
|
cluster_name: ${{ env.KIND_CLUSTER_NAME }}
|
|
config: kind.yaml
|
|
|
|
- name: Configuring and testing the Installation
|
|
run: |
|
|
kubectl cluster-info --context kind-${{ env.KIND_CLUSTER_NAME }}
|
|
kubectl get nodes
|
|
sudo apt-get install -y apache2-utils
|
|
kubectl config use-context kind-${{ env.KIND_CLUSTER_NAME }}
|
|
kubectl config view
|
|
|
|
- name: Helm chart lint
|
|
run: |
|
|
helm lint charts/fission-all/
|
|
|
|
- name: Install Skaffold
|
|
run: |
|
|
curl -Lo skaffold https://storage.googleapis.com/skaffold/releases/v2.14.0/skaffold-linux-amd64
|
|
sudo install skaffold /usr/local/bin/
|
|
skaffold version
|
|
|
|
- name: Install GoReleaser
|
|
uses: goreleaser/goreleaser-action@9c156ee8a17a598857849441385a2041ef570552 # v6.3.0
|
|
with:
|
|
install-only: true
|
|
version: "~> v2"
|
|
|
|
- name: Setup Prometheus Stack
|
|
run: |
|
|
helm repo add prometheus-community https://prometheus-community.github.io/helm-charts
|
|
helm repo update
|
|
kubectl create ns monitoring
|
|
helm install prometheus prometheus-community/kube-prometheus-stack -n monitoring \
|
|
--version 45.28.0 --set grafana.enabled=false --set alertmanager.enabled=false
|
|
|
|
- name: Build and Install Fission CLI
|
|
run: |
|
|
make debug-vars
|
|
make build-fission-cli
|
|
sudo make install-fission-cli
|
|
sudo chmod +x /usr/local/bin/fission
|
|
|
|
- name: Build and Install Fission
|
|
timeout-minutes: 10
|
|
run: |
|
|
kubectl create ns fission
|
|
make create-crds
|
|
SKAFFOLD_PROFILE=kind-ci-old make skaffold-deploy
|
|
|
|
- name: Port-forward fission components
|
|
run: |
|
|
kubectl port-forward svc/router 8888:80 -nfission &
|
|
|
|
- name: Get fission version
|
|
timeout-minutes: 10
|
|
run: |
|
|
fission version
|
|
|
|
- name: Integration tests
|
|
timeout-minutes: 90
|
|
run: |
|
|
export FUNCTION_NAMESPACE=fission-function
|
|
export BUILDER_NAMESPACE=fission-builder
|
|
./test/kind_CI.sh
|
|
|
|
- name: Collect Fission Dump
|
|
timeout-minutes: 5
|
|
if: ${{ always() }}
|
|
run: |
|
|
command -v fission && fission support dump
|
|
|
|
- name: Kind export logs
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
run: |
|
|
kind export logs --name kind kind-logs
|
|
|
|
- name: Backup prometheus data
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
run: |
|
|
TRACE=1 ./hack/backup-prometheus.sh
|
|
|
|
- name: Archive fission dump
|
|
timeout-minutes: 10
|
|
if: ${{ failure() || cancelled() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: fission-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
|
path: fission-dump/*.zip
|
|
retention-days: 5
|
|
|
|
- name: Archive prometheus dump
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: prom-dump-${{ github.run_id }}-${{ matrix.kindversion }}
|
|
path: /tmp/prometheus/*
|
|
retention-days: 5
|
|
|
|
- name: Archive kind logs
|
|
timeout-minutes: 10
|
|
if: ${{ always() }}
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: kind-logs-${{ github.run_id }}-${{ matrix.kindversion }}
|
|
path: kind-logs/*
|
|
retention-days: 5 |