mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
89 lines
3.6 KiB
YAML
89 lines
3.6 KiB
YAML
name: ansible-ceph-validate
|
|
|
|
# Static validation gate for the ansible/ceph stack. ci.yml only validates the
|
|
# Kubernetes/Flux surface (mise run k8s:validate); nothing there parses the ceph
|
|
# playbooks, inventory or scripts. Without this gate a broken playbook, host_var
|
|
# or script arg first executes during the post-merge PROD apply against real
|
|
# nodes. This job runs the existing local validators (yamllint + ansible-lint +
|
|
# shellcheck + syntax-check) with NO secrets and NO connection to any host.
|
|
#
|
|
# It lives in its own workflow (not a job in ci.yml) so the path filter below is
|
|
# workflow-scoped: `on.<event>.paths` gates the whole file. Adding the same
|
|
# filter inside ci.yml would gate every ci.yml job (k8s validate, tests) too.
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- 'ansible/ceph/**'
|
|
- '.github/workflows/ansible-ceph-validate.yml'
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- 'ansible/ceph/**'
|
|
- '.github/workflows/ansible-ceph-validate.yml'
|
|
|
|
# Read-only: checkout + tool downloads only. No writes through the token, no
|
|
# deploy credentials, no 1Password.
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ansible-ceph-validate-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
validate:
|
|
name: Validate ansible/ceph (lint + syntax)
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
defaults:
|
|
run:
|
|
working-directory: ansible/ceph
|
|
steps:
|
|
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Setup Mise
|
|
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
|
|
with:
|
|
# Install from ansible/ceph so the nested .mise.toml (pinned Python)
|
|
# is picked up alongside the root tools; the action trusts the whole
|
|
# repo via MISE_TRUSTED_CONFIG_PATHS, so no `mise trust` is needed.
|
|
working_directory: ansible/ceph
|
|
|
|
# Create the project .venv exactly as `mise run setup` does: pip install
|
|
# requirements.txt (pins ansible-core, ansible-lint, yamllint) and the
|
|
# ansible-galaxy collections (ansible.posix, community.general) that
|
|
# ansible-lint / syntax-check need to resolve modules. PyPI + Galaxy only;
|
|
# no secrets.
|
|
- name: Install ansible tooling
|
|
run: mise run setup
|
|
|
|
# yamllint + ansible-lint + shellcheck (scripts/*.sh). None need a live
|
|
# inventory or secrets; shellcheck ships on ubuntu-latest runners.
|
|
- name: Lint (yamllint + ansible-lint + shellcheck)
|
|
run: mise run lint
|
|
|
|
# ansible-playbook --syntax-check needs *an* inventory, but the real
|
|
# inventory.ini is TF-generated and gitignored, so it does not exist in
|
|
# CI. A syntax-check only parses YAML/role structure, so any valid
|
|
# inventory works: write a throwaway localhost inventory and point CEPH_ENV
|
|
# at it (the ceph:check task honours an exported CEPH_ENV). This never
|
|
# connects to a host.
|
|
- name: Syntax-check playbooks
|
|
env:
|
|
CEPH_ENV: /tmp/ci-inventory.ini
|
|
run: |
|
|
printf '[all]\nlocalhost ansible_connection=local\n' > /tmp/ci-inventory.ini
|
|
mise run check
|
|
|
|
# Byte-compile the helper scripts so a broken generator is caught here,
|
|
# not mid-provision. (shellcheck above covers the *.sh scripts.)
|
|
# Covers roles/*/files/*.py too: those ship to the nodes via
|
|
# ansible.builtin.script, so a syntax error there fails mid-converge.
|
|
- name: Compile Python scripts
|
|
run: |
|
|
mise exec -- python -m py_compile \
|
|
$(find scripts roles -name '*.py' -not -path '*/__pycache__/*')
|