-
Notifications
You must be signed in to change notification settings - Fork 4
175 lines (169 loc) · 6.08 KB
/
Copy pathconformance.yaml
File metadata and controls
175 lines (169 loc) · 6.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
name: Conformance
on:
schedule:
- cron: '0 4 * * *' # 04:00 UTC nightly
push:
tags:
- 'v*'
pull_request:
paths:
- 'test/conformance/**'
- 'internal/**'
- 'api/**'
- '.github/workflows/conformance.yaml'
workflow_dispatch:
jobs:
negative:
name: Negative (schema and CEL deny paths)
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- uses: helm/kind-action@v1
with:
cluster_name: paperclip-conformance
- name: Install CRDs
run: make install
- name: Run negative conformance
env:
KUBECONFIG: /home/runner/.kube/config
run: make conformance-negative
# Advisory on PRs until the kind conformance harness is verified stable for
# paperclip's managed-DB workload; flip continue-on-error off once green.
# See https://github.com/paperclipinc/paperclip-operator/issues (conformance
# harness hardening follow-up).
# These jobs build/load the operator image, deploy the controller-manager, and
# run operator-dependent conformance categories on kind. The Negative job
# above is API-server-only and stays required/blocking.
idempotency:
name: Idempotency
runs-on: ubuntu-latest
timeout-minutes: 45
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- uses: helm/kind-action@v1
with:
cluster_name: paperclip-conformance
- name: Build and load operator image
run: |
make docker-build IMG=paperclip-operator:dev
kind load docker-image paperclip-operator:dev --name paperclip-conformance
- name: Deploy operator
run: make deploy IMG=paperclip-operator:dev
- name: Wait for operator to be Available
# make deploy only applies manifests and returns immediately; the
# controller-manager Pod still has to pull its image, start, and win
# leader election before it reconciles anything. Block here until the
# Deployment is Available so the conformance suite never races the
# operator. Mirrors openclaw-operator's `helm install --wait`.
run: |
kubectl rollout status \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=10m
kubectl wait --for=condition=Available \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=5m
- name: Run idempotency conformance
env:
KUBECONFIG: /home/runner/.kube/config
run: make conformance-idempotency
gitops-coexistence:
name: GitOps coexistence
runs-on: ubuntu-latest
timeout-minutes: 45
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- uses: helm/kind-action@v1
with:
cluster_name: paperclip-conformance
- name: Build and load operator image
run: |
make docker-build IMG=paperclip-operator:dev
kind load docker-image paperclip-operator:dev --name paperclip-conformance
- name: Deploy operator
run: make deploy IMG=paperclip-operator:dev
- name: Wait for operator to be Available
run: |
kubectl rollout status \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=10m
kubectl wait --for=condition=Available \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=5m
- name: Run gitops coexistence conformance
env:
KUBECONFIG: /home/runner/.kube/config
run: make conformance-gitops
failure-modes:
name: Failure modes
runs-on: ubuntu-latest
timeout-minutes: 45
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- uses: helm/kind-action@v1
with:
cluster_name: paperclip-conformance
- name: Build and load operator image
run: |
make docker-build IMG=paperclip-operator:dev
kind load docker-image paperclip-operator:dev --name paperclip-conformance
- name: Deploy operator
run: make deploy IMG=paperclip-operator:dev
- name: Wait for operator to be Available
run: |
kubectl rollout status \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=10m
kubectl wait --for=condition=Available \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=5m
- name: Run failure-injection conformance
env:
KUBECONFIG: /home/runner/.kube/config
run: make conformance-failure
upgrade:
name: Upgrade path
runs-on: ubuntu-latest
timeout-minutes: 60
continue-on-error: true
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- uses: helm/kind-action@v1
with:
cluster_name: paperclip-conformance
- name: Build and load operator image
run: |
make docker-build IMG=paperclip-operator:dev
kind load docker-image paperclip-operator:dev --name paperclip-conformance
- name: Deploy operator
run: make deploy IMG=paperclip-operator:dev
- name: Wait for operator to be Available
run: |
kubectl rollout status \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=10m
kubectl wait --for=condition=Available \
deploy -l control-plane=controller-manager \
-n paperclip-operator-system --timeout=5m
- name: Run upgrade-path conformance
env:
KUBECONFIG: /home/runner/.kube/config
run: make conformance-upgrade