-
Notifications
You must be signed in to change notification settings - Fork 1.7k
161 lines (138 loc) · 6.13 KB
/
Copy pathlint_helm_chart.yaml
File metadata and controls
161 lines (138 loc) · 6.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
name: Lint Opik Helm Chart
run-name: "Lint Opik Helm Chart ${{ github.ref_name }} by @${{ github.actor }}"
on:
workflow_dispatch:
pull_request:
paths:
- "deployment/helm_chart/opik/**"
push:
branches:
- 'main'
paths:
- "deployment/helm_chart/opik/**"
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
# This workflow only reads the repo (lint + render); no write access needed.
permissions:
contents: read
jobs:
lint-helm-chart:
runs-on: ubuntu-latest
timeout-minutes: 5
strategy:
fail-fast: false
matrix:
# Prove dual compatibility: the chart must keep working on Helm 3.x
# while also rendering cleanly under Helm 4.x (DND-537).
helm-version:
- v3.21.0
- v4.2.0
name: lint-helm-chart (Helm ${{ matrix.helm-version }})
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Install Helm ${{ matrix.helm-version }}
uses: azure/setup-helm@v4.3.1
with:
version: ${{ matrix.helm-version }}
- name: Run lint on Helm chart
run: |
set -e
cd deployment/helm_chart/opik
helm repo add mysql https://comet-ml.github.io/comet-mysql-helm/
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo add clickhouse-operator https://docs.altinity.com/clickhouse-operator
helm dependency build
helm lint --values values.yaml .
cd -
# Assert the rendered content of specific resources (e.g. the `opik.probe`
# helper) via helm-unittest. Tests live in deployment/helm_chart/opik/tests/.
unittest-helm-chart:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Install Helm
uses: azure/setup-helm@v4.3.1
with:
version: v3.21.0
- name: Install helm-unittest plugin
run: helm plugin install https://github.com/helm-unittest/helm-unittest
- name: Run helm unittest
run: |
set -e
cd deployment/helm_chart/opik
helm repo add mysql https://comet-ml.github.io/comet-mysql-helm/
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo add clickhouse-operator https://docs.altinity.com/clickhouse-operator
helm dependency build
helm unittest .
cd -
# Prove the chart renders equivalently under Helm 3.x and Helm 4.x so we can ship
# Helm 4 support without changing behavior for Helm 3 users (DND-537). Each version
# resolves its own dependencies (`helm dependency build`) and renders from scratch.
# Helm 4 only differs from Helm 3 in trailing whitespace it emits between manifests,
# which YAML ignores and does not change any rendered Kubernetes object — so we
# compare after stripping trailing whitespace and blank lines.
render-equality:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Render with Helm 3.x
uses: azure/setup-helm@v4.3.1
with:
version: v3.21.0
- name: helm template (Helm 3.x)
run: |
set -e
cd deployment/helm_chart/opik
rm -rf charts Chart.lock
helm repo add mysql https://comet-ml.github.io/comet-mysql-helm/
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo add clickhouse-operator https://docs.altinity.com/clickhouse-operator
helm dependency build
helm template opik . --values values.yaml > "${RUNNER_TEMP}/render-helm3.yaml"
cd -
- name: Render with Helm 4.x
uses: azure/setup-helm@v4.3.1
with:
version: v4.2.0
- name: helm template (Helm 4.x)
run: |
set -e
cd deployment/helm_chart/opik
# Wipe Helm 3's resolved deps so Helm 4 runs its own dependency resolution.
rm -rf charts Chart.lock
helm repo add mysql https://comet-ml.github.io/comet-mysql-helm/
helm repo add bitnami https://charts.bitnami.com/bitnami
helm repo add clickhouse-operator https://docs.altinity.com/clickhouse-operator
helm dependency build
helm template opik . --values values.yaml > "${RUNNER_TEMP}/render-helm4.yaml"
cd -
- name: Diff rendered output (semantically; must be identical)
run: |
set -e
# Compare by parsing every rendered YAML document and re-serializing it
# canonically (sorted keys), instead of a line-based diff. This ignores the
# ONLY thing Helm 4 changes vs Helm 3 — cosmetic inter-document spacing and
# trailing whitespace — while preserving real content, including blank lines
# *inside* block scalars (e.g. embedded config in ConfigMaps). A line-based
# blank-line strip would hide those; a YAML round-trip does not.
canonicalize() {
python3 - "$1" <<'PY'
import sys, yaml
docs = [d for d in yaml.safe_load_all(open(sys.argv[1])) if d is not None]
sys.stdout.write(yaml.safe_dump_all(docs, sort_keys=True, default_flow_style=False))
PY
}
canonicalize "${RUNNER_TEMP}/render-helm3.yaml" > "${RUNNER_TEMP}/render-helm3.norm.yaml"
canonicalize "${RUNNER_TEMP}/render-helm4.yaml" > "${RUNNER_TEMP}/render-helm4.norm.yaml"
if ! diff -u "${RUNNER_TEMP}/render-helm3.norm.yaml" "${RUNNER_TEMP}/render-helm4.norm.yaml"; then
echo "::error::Rendered manifests differ between Helm 3.x and Helm 4.x. The chart must render equivalently on both."
exit 1
fi
echo "Helm 3.x and Helm 4.x produce equivalent rendered manifests."